CVE-2024-12646
The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability, allowing attackers to delete arbitrary files on the user's system.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
- EPSS probability
- 0.31%
- CWE
- CWE-352, CWE-36
- Published
- 2024-12-16
- Last modified
- 2026-03-13
Affected products
- Chunghwa Telecom topm-client
Weakness type
Related vulnerabilities
- CVE-2026-87449 — Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36...
- CVE-2026-9215 — A CSRF vulnerability exists in certain NETGEAR XR series devices
- CVE-2026-86724 — AVideo YPTWallet saveBalance.php Cross-Site Request Forgery
- CVE-2026-86719 — WWBN AVideo CustomizeUser Cross-Site Request Forgery Session Hijacking
- CVE-2026-86718 — WWBN AVideo Cross-Site Request Forgery via deleteHistory.json.php
- CVE-2026-86135 — Dimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of Service
- CVE-2026-33920 — Cross-site request forgery in the Guardian/CMC login before 26.3.0
- CVE-2026-76961 — Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)