CVE-2024-54764: Medium severity iptime a2004 vulnerability
Published Jan 6, 2025
·Updated
An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.
Affected Software
1 affected component
IPTIME A2004
Event History
Jan 6, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-54764?
CVE-2024-54764 has been rated as a high severity vulnerability due to its potential for exposing sensitive information without user authentication.
2
How do I fix CVE-2024-54764?
To fix CVE-2024-54764, update the ipTIME A2004 firmware to the latest version provided by the vendor.
3
What kind of information can be accessed due to CVE-2024-54764?
CVE-2024-54764 allows attackers to access sensitive information such as user credentials or network configurations without authentication.
4
Which component is affected by CVE-2024-54764?
CVE-2024-54764 affects the /login/hostinfo2.cgi component of the ipTIME A2004 router.
5
Who is affected by CVE-2024-54764?
Users of the ipTIME A2004 router running version 12.17.0 are affected by CVE-2024-54764.