CVE-2024-54982

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 19, 2024
Updated: Jan 15, 2025
CWE ID 306

Summary

CVE-2024-54982 is a vulnerability affecting the Quectel BC25 device with firmware version BC25PAR01A06. This issue permits unauthenticated attackers to bypass the authentication process through a specially crafted NAS (Network Attached Storage) message. Despite Quectel's disputes, the vulnerability lies in the chipset supply chain, making it a broader concern beyond their specific products.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share