ZeroHour

CVE-2024-7694

KEVniche

Unrestricted File Upload RCE in TeamT5 ThreatSonar Anti-Ransomware

CISA: TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability

CVSS 3.1
7.2 high
EPSS
2%p77
Published
()
KEV added
AI analysis

TeamT5 ThreatSonar Anti-Ransomware fails to properly validate the content of uploaded files, allowing unrestricted upload of dangerous file types (CWE-434). The flaw is triggered by a remote attacker who already holds administrator privileges on the ThreatSonar platform; after authenticating as an admin, the attacker uploads a malicious file that is used to execute arbitrary system commands on the underlying server. Successful exploitation results in full compromise of the host running the product, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.2). All deployments of TeamT5 ThreatSonar Anti-Ransomware are affected per CISA; the available data does not specify affected or fixed version ranges. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-02-17 following evidence of active exploitation, though no public proof-of-concept is known and ransomware use is unconfirmed.

What to do: Apply mitigations per TeamT5's vendor instructions, following CISA BOD 22-01 timelines for federal agencies, or discontinue use of the product if mitigations are unavailable. Restrict and audit administrator accounts on the ThreatSonar platform, review upload activity and system logs for unexpected commands or processes on the host, and verify current mitigation guidance against the latest TeamT5 advisory since specific fixed versions are not listed in this data.

Affected
teamt5 ThreatSonar Anti-Ransomware
Estimated exposure
nichelikely no more than a few thousand deployments, concentrated in Taiwan (estimate; no public install counts) — ThreatSonar is a specialized anti-ransomware threat-detection platform from small Taiwanese vendor TeamT5, deployed mainly in Taiwanese government and enterprise environments, and no public install-base or internet-exposure scan counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.

CISA Known Exploited Vulnerability
Affected
TeamT5 ThreatSonar Anti-Ransomware
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
teamt5
Products
threatsonar anti-ransomware
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news