CVE-2024-54764
Exposure of Sensitive Information to an Unauthorized Actor
Record summary
CVE-2024-54764 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 28, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 7, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Nuclei templates
1ProjectDiscoveryMEDIUMipTIME A2004 - Unauthorized AccessCVSS 6.5
An access control issue exists in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 that allows attackers to obtain sensitive information without authentication. The vulnerability allows unauthenticated access to device settings and configuration information.
Impact
Unauthenticated attackers can access sensitive device settings and configuration information through the hostinfo2.cgi endpoint.
Remediation
Update ipTIME A2004 router to a version later than 12.17.0 that addresses the unauthorized access vulnerability.
Source: ProjectDiscovery