ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
Is CVE-2024-7694 exploited?
Listed in the CISA KEV catalog on 2026-02-17.
Federal remediation due 2026-03-10.
Past that date by 158 days.
EPSS puts exploitation in the next 30 days at 2%.
Public exploit code: none found in monitored sources.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2024-7694
PlainSec has not published a story about this CVE.