CVE-2024-7694 is an unrestricted file upload vulnerability in TeamT5 ThreatSonar Anti-Ransomware that allows remote attackers with admin privileges to upload malicious files and execute arbitrary system commands. This vulnerability is actively exploited in the wild and listed in CISA KEV catalog.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2024-08-12
Added to CISA KEV: 2026-02-17 554 DAYS BETWEEN CVE AND KEV
CVE-2024-7694 is a critical security vulnerability affecting ThreatSonar Anti-Ransomware by the Taiwanese cybersecurity firm TeamT5 [3] [2].
The following details summarize the current understanding of this vulnerability:
(NVD) TeamT5 told SecurityWeek the exploitation occurred in 2024, targeted only a small number of customers, and was assessed as a highly coordinated campaign aimed at compromising high-profile downstream environments (SecurityWeek reporting, 24 Feb 2026). (SecurityWeek) TeamT5 further assessed the…
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
Description. ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator ...
This particular flaw, identified as CVE-2024-7694, exists within the ThreatSonar Anti-Ransomware product, which was created by the Taiwanese cybersecurity firm TeamT5.Attribution in cyberspace is often a complex and speculative process. At present, there is no public information definitively identif…
CISA added CVE-2024-7694 to the Known Exploited Vulnerabilities catalog after hackers exploited a critical arbitrary file-upload flaw in ...