CVE-2024-54982
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 19, 2024
Updated: Jan 15, 2025
CWE ID 306
Summary
CVE-2024-54982 is a vulnerability affecting the Quectel BC25 device with firmware version BC25PAR01A06. This issue permits unauthenticated attackers to bypass the authentication process through a specially crafted NAS (Network Attached Storage) message. Despite Quectel's disputes, the vulnerability lies in the chipset supply chain, making it a broader concern beyond their specific products.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.