CVE-2024-54763
Exposure of Sensitive Information to an Unauthorized Actor
Record summary
CVE-2024-54763 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 28, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 7, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Nuclei templates
1ProjectDiscoveryMEDIUMipTIME A2004 - Unauthorized AccessCVSS 5.3
An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.
Impact
Unauthenticated attackers can access sensitive device configuration information through the hostinfo.cgi endpoint without authentication.
Remediation
Update ipTIME A2004 router to a version later than 12.17.0 that addresses the unauthorized access vulnerability.
Source: ProjectDiscovery