CVE-2024-7694

HIGH KEV

Teamt5 Threatsonar Anti-ransomware < 3.5.0 - Unrestricted File Upload

Title source: rule

Description

ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.

Scores

CVSS v3 7.2
EPSS 0.0122
EPSS Percentile 78.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2026-02-17
VulnCheck KEV 2026-02-17
ENISA EUVD EUVD-2024-48579

Classification

CWE
CWE-434
Status published

Affected Products (1)

teamt5/threatsonar_anti-ransomware < 3.5.0

Timeline

Published Aug 12, 2024
KEV Added Feb 17, 2026
Tracked Since Feb 18, 2026