Record summary

CVE-2024-54763 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 28, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 7, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMipTIME A2004 - Unauthorized AccessCVSS 5.3

An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

Impact

Unauthenticated attackers can access sensitive device configuration information through the hostinfo.cgi endpoint without authentication.

Remediation

Update ipTIME A2004 router to a version later than 12.17.0 that addresses the unauthorized access vulnerability.

WeaknessesCWE-284
Authorsritikchaddha
Template tagscvecve2024iptimerouterunauthexposurevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Shodan: http.title:"ipTIME"
FOFA: title="ipTIME"

Source: ProjectDiscovery

References

2