🔐 CVE Alert

CVE-2024-7694

HIGH 7.2 ⚠️ CISA KEV

TeamT5 ThreatSonar Anti-Ransomware - Arbitrary File Upload

CVSS Score
7.2
EPSS Score
1.6%
EPSS Percentile
82th

ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.

CWE CWE-434
Vendor teamt5
Product threatsonar anti-ransomware
Published Aug 12, 2024
Last Updated Feb 18, 2026

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

TeamT5 / ThreatSonar Anti-Ransomware
0 ≤ 3.4.5

References

NVD ↗ CVE.org ↗ EPSS Data ↗
twcert.org.tw: https://www.twcert.org.tw/tw/cp-132-7998-d76dd-1.html twcert.org.tw: https://www.twcert.org.tw/en/cp-139-8000-e5a5c-2.html cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7694