Arbitrary File Deletion Risk in Chunghwa Telecom's topm-client Application
CVE-2024-12646
What is CVE-2024-12646?
CVE-2024-12646 identifies a serious security vulnerability within Chunghwa Telecom's topm-client application. This vulnerability enables unauthenticated remote attackers to exploit a lack of CSRF protection and an Absolute Path Traversal flaw in the application's APIs. This can lead to arbitrary file deletion on the user's system, increasing the risk of data loss and unauthorized access. Users and network administrators are urged to review their use of topm-client and apply any available security updates to mitigate this critical risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
topm-client 0.3.14 <= 0.3.17
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
