AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-12644

HIGH · CVSS 7.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-12-16 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.1. It may be remotely exploitable.

CVE
CVE-2024-12644
Severity
HIGH
CVSS
7.1
EPSS
0.29%

Original NVD Description

The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability. Attackers can copy arbitrary files on the user's system and paste them into any path, which poses a potential risk of information leakage or could consume hard drive space by copying files in large volumes.