S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 11, 2025

CVE-2024-54763 Scanner

CVE-2024-54763 Scanner - Unauthorized Admin Access vulnerability in ipTIME A2004

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
6.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.
Description

An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Sep 18, 2026View on NVD →
Detail

ipTIME A2004 is a widely used wireless router from ipTIME, commonly utilized by both home users and small businesses for network connectivity. This router is known for its reliable performance and ease of configuration, making it a popular choice in various regions where the brand is available. Users employ it to manage internet connectivity and network security settings for multiple devices within a network environment. The router supports a variety of network protocols and offers features such as wireless security, parental controls, and guest networking. Due to its affordability and feature set, the ipTIME A2004 is a common fixture in households and small enterprises looking for robust internet access solutions.

The unauthorized admin access vulnerability in ipTIME A2004 allows attackers to gain access to sensitive information or configuration settings without authentication. This issue arises from weak access control checks that fail to adequately protect administrative endpoints. As a result, unauthorized parties can exploit this weakness to retrieve sensitive data, such as network configurations and host information, possibly compromising the network's security integrity. The vulnerability primarily affects the /login/hostinfo.cgi component and has been identified as a medium severity issue. Its discovery highlights the importance of robust access controls in network hardware to protect sensitive data from unauthorized exposure.

This vulnerability is characterized by improper access control mechanisms within the ipTIME A2004 router's administration interface. The specific endpoint affected is /login/hostinfo.cgi, which normally requires authenticated administrative access. However, due to this vulnerability, attackers can directly access this endpoint without any authentication, leading to exposure of potentially sensitive information. The delivery of the attack is facilitated through a simple HTTP GET request, which returns sensitive data due to improper authorization checks. The presence of this vulnerability underscores the need for improved access control implementations that can prevent unauthorized data retrieval.

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, potentially allowing attackers to view network configuration details. Such exposure could assist in further exploiting the network, either by informing subsequent attacks or enabling unauthorized network changes. This could result in interception or monitoring of network traffic, unauthorized usage of network resources, or even disruption of network services. Additionally, attackers with access to configuration settings might be able to weaken security measures, leading to more severe security breaches over time.

REFERENCES

Solution Advice
  • Implement strong authentication mechanisms to protect sensitive administrative endpoints.
  • Regularly update the router's firmware to ensure all security patches are applied.
  • Restrict access to administrative interfaces to trusted networks only.
  • Configure firewalls to block unauthorized access attempts to the router's administrative functions.
  • Educate users on strong password practices to further secure access to the router.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-54763 Scanner - Unauthorized Admin Access vulnerability in ipTIME A2004 | S4E