An access control issue exists in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 that allows attackers to obtain sensitive information without authentication. The vulnerability allows unauthenticated access to device settings and configuration information.
id: CVE-2024-54764
info:
name: ipTIME A2004 - Unauthorized Access
author: ritikchaddha
severi
...