CVE-2024-12644 - CVE House
Back to Database
Status published High CVE-2024-12644

Chunghwa Telecom tbm-client - Arbitrary File Copy and Paste

Vulnerability Description

The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability. Attackers can copy arbitrary files on the user's system and paste them into any path, which poses a potential risk of information leakage or could consume hard drive space by copying files in large volumes.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-12644

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Chunghwa Telecom

View all reports →

Affected Software

tbm-client
Vulnerable Versions:
0.3.15

Timeline

Official Publish: December 16th, 2024
Last Modified: December 16th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L

Weaknesses (CWE)