Arbitrary File Read Vulnerability in Chunghwa Telecom's Topm-client
CVE-2024-12645
What is CVE-2024-12645?
CVE-2024-12645 is a critical vulnerability affecting Chunghwa Telecom's topm-client, characterized by an Arbitrary File Read flaw. This vulnerability stems from the application's failure to implement Cross-Site Request Forgery (CSRF) protection on its APIs, enabling unauthenticated remote attackers to exploit this oversight via phishing attacks. Compounding the risk, one of the APIs is vulnerable to Relative Path Traversal, allowing attackers to access and read arbitrary files on an end user's local system. Organizations using topm-client are strongly advised to review their security protocols and implement necessary updates to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
topm-client 0.3.14 <= 0.3.17
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
