PT-2024-17689 · Chunghwa Telecom · Topm-Client

Chumy Tsai

·

Published

2024-12-16

·

Updated

2024-12-16

·

CVE-2024-12645

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions topm-client from Chunghwa Telecom (affected versions not specified)
Description The topm-client from Chunghwa Telecom has an issue that allows attackers to read arbitrary files on the user's system. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains a Relative Path Traversal vulnerability, which allows attackers to read arbitrary files on the user's system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Relative Path Traversal

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12645

Affected Products

Topm-Client