CVE-2024-7694

unknown KEV
Published 2026-02-17 · Modified 2026-02-17
CVSS v3
CVSS v2
VIR risk
1.5

Description

TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system commands on the server.

CISA KEV

Vendor
TeamT5
Product
ThreatSonar Anti-Ransomware
Due date
2026-03-10

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://teamt5.org/en/posts/vulnerability-notice-threat-sonar-anti-ransomware-20240715/ ; https://www.twcert.org.tw/en/cp-139-8000-e5a5c-2.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-7694

Exploits

References

Verify integrity in audit chain (admin only). AS-IS.