Record summary

CVE-2024-54764 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 28, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 7, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMipTIME A2004 - Unauthorized AccessCVSS 6.5

An access control issue exists in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 that allows attackers to obtain sensitive information without authentication. The vulnerability allows unauthenticated access to device settings and configuration information.

Impact

Unauthenticated attackers can access sensitive device settings and configuration information through the hostinfo2.cgi endpoint.

Remediation

Update ipTIME A2004 router to a version later than 12.17.0 that addresses the unauthorized access vulnerability.

WeaknessesCWE-284
Authorsritikchaddha
Template tagscvecve2024iptimerouterunauthexposurevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Shodan: http.title:"ipTIME"
FOFA: title="ipTIME"

Source: ProjectDiscovery

References

2