CVE-2024-1651

CRITICAL

Torrentpier - Insecure Deserialization

Title source: rule
STIX 2.1

Description

Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.

Exploits (4)

nomisec WORKING POC 14 stars
by sharpicx · poc
https://github.com/sharpicx/CVE-2024-1651-PoC
nomisec WORKING POC 3 stars
by hy011121 · poc
https://github.com/hy011121/CVE-2024-1651-exploit-RCE
nomisec WORKING POC
by killukeren · poc
https://github.com/killukeren/cve-2024-1651
nomisec WORKING POC
by Whiteh4tWolf · poc
https://github.com/Whiteh4tWolf/CVE-2024-1651-PoC

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://fluidattacks.com/advisories/xavi/

Scores

CVSS v3 10.0
EPSS 0.8059
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (2)
torrentpier/torrentpier 2.4.1
torrentpier/torrentpier 0Packagist
Published Feb 20, 2024
Tracked Since Feb 18, 2026