CVE-2024-54767 Details
Description
An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication. NOTE: this is disputed by the Supplier because it cannot be reproduced, and the issue report focuses on an unintended configuration with direct Internet exposure.
A vulnerability exists in the AVM FRITZ!Box 7530 AX router, specifically in version 7.59, allowing unauthorized access to sensitive information through the '/juis_boxinfo.xml' file. This issue arises from an access control flaw that permits remote attackers to retrieve data without authentication. However, the reported vulnerability is disputed by the supplier, who states it cannot be reproduced and attributes the issue to an unintended configuration with direct Internet exposure.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 6, 2025CISA-ADP
Assessed Jan 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Shuanunio/CVE_Requests/blob/main/AVM/fritz/AVM_FRITZ%21Box_7530%20AX_unauthorized_access_vulnerability_first.md | [email protected] | ExploitTechnical Description |
| https://github.com/Shuanunio/CVE_Requests/issues/1 | [email protected] | Issue TrackingTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-203 | Observable Discrepancy | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| AVM FRITZ!Box 7530 AX | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2025 | CVE Modified | [email protected] |
| Jan 7, 2025 | CVE Modified | CISA-ADP |
| Jan 6, 2025 | New CVE Received | [email protected] |
Volerion