CVE-2024-7694
KEVnicheUnrestricted File Upload RCE in TeamT5 ThreatSonar Anti-Ransomware
CISA: TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
TeamT5 ThreatSonar Anti-Ransomware fails to properly validate the content of uploaded files, allowing unrestricted upload of dangerous file types (CWE-434). The flaw is triggered by a remote attacker who already holds administrator privileges on the ThreatSonar platform; after authenticating as an admin, the attacker uploads a malicious file that is used to execute arbitrary system commands on the underlying server. Successful exploitation results in full compromise of the host running the product, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.2). All deployments of TeamT5 ThreatSonar Anti-Ransomware are affected per CISA; the available data does not specify affected or fixed version ranges. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-02-17 following evidence of active exploitation, though no public proof-of-concept is known and ransomware use is unconfirmed.
What to do: Apply mitigations per TeamT5's vendor instructions, following CISA BOD 22-01 timelines for federal agencies, or discontinue use of the product if mitigations are unavailable. Restrict and audit administrator accounts on the ThreatSonar platform, review upload activity and system logs for unexpected commands or processes on the host, and verify current mitigation guidance against the latest TeamT5 advisory since specific fixed versions are not listed in this data.
| teamt5 ThreatSonar Anti-Ransomware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
- Affected
- TeamT5 ThreatSonar Anti-Ransomware
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- teamt5
- Products
- threatsonar anti-ransomware
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H