🔴 CVE-2024-7694

CVE-2024-7694 is an unrestricted file upload vulnerability in TeamT5 ThreatSonar Anti-Ransomware that allows remote attackers with admin privileges to upload malicious files and execute arbitrary system commands. This vulnerability is actively exploited in the wild and listed in CISA KEV catalog.

← Back to Overview
HIGH_RISK
Risk Level
7.2
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2024-08-12

Added to CISA KEV: 2026-02-17 554 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2024-7694 is a critical security vulnerability affecting ThreatSonar Anti-Ransomware by the Taiwanese cybersecurity firm TeamT5 [3] [2].

The following details summarize the current understanding of this vulnerability:

Exploitation and Threat Actor Usage
  • Active Exploitation: The vulnerability has been confirmed as actively exploited in the wild, leading to its inclusion in the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog [4] [5].
  • Threat Actors: TeamT5 has assessed the exploitation activity as a highly coordinated campaign likely conducted by China-nexus Advanced Persistent Threat (APT) clusters, specifically tracked by the vendor as "Slime57" and "Slime62" [1].
  • Nature of Attacks: The campaign was targeted, affecting a small number of high-profile downstream environments. Attackers utilized large-scale proxying through compromised Taiwanese devices to obscure the origin of their operations [1].
Attack Method and Requirements
  • Vulnerability Type: The flaw is an improper input validation issue regarding the content of uploaded files [3].
  • Requirements: Successful exploitation requires the attacker to already possess administrator privileges on the product platform. With this access, a remote attacker can upload malicious files to the server [2].
Impact
  • Access/Impact: Once a malicious file is uploaded, it can be used to execute arbitrary system commands on the server, resulting in full system compromise [2].
Patch and Mitigation Status
  • Patch Availability: TeamT5 published patch guidance in July 2024 [1].
  • Cloud Service: The vendor confirmed that its cloud service was updated on July 12, 2024, to remediate the issue [1].
  • Mitigation: Organizations using on-premises versions of ThreatSonar should ensure they have applied the official patches provided by TeamT5.

Sources

  1. Chinese APT-linked exploitation of TeamT5 ThreatSonar...

    (NVD) TeamT5 told SecurityWeek the exploitation occurred in 2024, targeted only a small number of customers, and was assessed as a highly coordinated campaign aimed at compromising high-profile downstream environments (SecurityWeek reporting, 24 Feb 2026). (SecurityWeek) TeamT5 further assessed the…

  2. CVE-2024-7694 : ThreatSonar Anti-Ransomware from TeamT5 does not ...

    ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.

  3. CVE-2024-7694 Detail - NVD

    Description. ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator ...

  4. CISA Warns of Actively Exploited Anti-Ransomware... | SecurityNews

    This particular flaw, identified as CVE-2024-7694, exists within the ThreatSonar Anti-Ransomware product, which was created by the Taiwanese cybersecurity firm TeamT5.Attribution in cyberspace is often a complex and speculative process. At present, there is no public information definitively identif…

  5. CISA Adds CVE-2024-7694 to Known Exploited ...

    CISA added CVE-2024-7694 to the Known Exploited Vulnerabilities catalog after hackers exploited a critical arbitrary file-upload flaw in ...