CVE-2024-48778

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 863

Summary

CVE-2024-48778 is a vulnerability affecting the GIANT MANUFACTURING CO., LTD RideLink firmware update process, version 2.0.7. This issue permits remote attackers to gain access to sensitive information during the update procedure, posing a significant risk to user privacy. Attackers can exploit this vulnerability without requiring authentication or physical access, making it a potential threat to connected e-bikes or similar devices using this software. The vulnerability calls for immediate attention from RideLink users and the development team to implement patches or mitigations to protect against potential data exposures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share