CVE-2024-55371
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 73
Summary
CVE-2024-55371 is a file upload vulnerability affecting Wallos version 2.38.2 and below. This issue resides in the restore backup function, which enables authenticated users to upload ZIP files to restore backups. Upon upload, the contents of the ZIP files are extracted on the server. An attacker, even without administrative privileges, can exploit this vulnerability to install a web shell by uploading a malicious ZIP file. Subsequently, the attacker gains the ability to execute arbitrary commands on the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.