CVE report
CVE-2024-24809high
Traccar - Unrestricted File Upload
Events 90d
268
Distinct IPs
123
Severity
high
CISA KEV
Not listed
Detection signature
An event counts toward CVE-2024-24809 when its URL path contains any of these (case-insensitive). This is what our matching is based on.
- · /api/devices
- · /api/session
- · /api/devices//image
Pre-disclosure activity
all early actors →Analysing probe history around the publication date…
Recent probe volume (last 7 days)
peak: 23 events/dayeventsdistinct IPs
Downloads & integrations
Top sources probing for CVE-2024-24809
- 124.198.131.18521 eventsUnited States· 1337 Services GmbH
- 66.154.119.22417 eventsUnited States· CYBERCON, INC.
- 185.242.3.56 eventsThe Netherlands· Netiface America, Inc.
- 45.156.128.1085 eventsPortugal
- 45.156.129.1554 eventsPortugal
- 109.105.209.174 eventsPortugal
- 45.156.129.1624 eventsPortugal
- 45.156.129.1284 eventsPortugal
- 45.156.128.1114 eventsPortugal
- 109.105.210.834 eventsPortugal
- 185.226.197.684 eventsPortugal
- 45.156.128.1064 eventsPortugal
- 45.156.129.1614 eventsPortugal
- 185.226.196.273 eventsPortugal
- 185.226.197.653 eventsPortugal
- 45.156.128.1073 eventsPortugal
- 45.156.129.1543 eventsPortugal
- 45.156.129.1693 eventsPortugal
- 185.226.197.623 eventsPortugal
- 109.105.209.193 eventsPortugal
- 45.156.129.1173 eventsPortugal
- 185.226.198.43 eventsPortugal· Sistemas Informaticos, S.A.
- 185.226.198.53 eventsPortugal· Sistemas Informaticos, S.A.
- 45.156.128.1703 eventsPortugal
- 185.180.141.543 eventsPortugal
- 45.156.128.1513 eventsPortugal
- 109.105.209.183 eventsPortugal
- 45.156.129.1103 eventsPortugal
- 185.226.197.643 eventsPortugal
- 185.226.196.283 eventsPortugal
Top networks the attempts come from
- AS211680 Sistemas Informaticos, S.A.80 IPs · 145 ev
- AS21859 Zenlayer Inc34 IPs · 72 ev
- AS210558 1337 Services GmbH1 IPs · 21 ev
- AS7393 CYBERCON, INC.1 IPs · 17 ev
- AS401626 Netiface America, Inc.1 IPs · 6 ev
- AS211590 Bucklog SARL4 IPs · 5 ev
- AS197170 TechTies Inc.1 IPs · 1 ev
- AS135377 UCLOUD INFORMATION TECHNOLOGY HK LIMITED1 IPs · 1 ev
Fingerprints of the clients exploiting this
The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.
ja4h: ge11nn0400_88d30a62b7adja4h: ge11nn06en_34bb3a836f3bja4h: ge11nn0300_0db47b7d240dja4h: ge11nn14en_068ebe3632ecja4h: ge11nn0400_81183b25faaeja4h: ge11nn0400_ef4d07580f66ja4: t13i250900_b78ed14e2fd0_e7c285222651ja4: t12i330500_5172cef6ed69_021165082e1cja4: t13i351200_bfa337485184_678a800b2221ja4: t13i1010h2_18ef40b21276_879711aa9f16
Sample request paths observed
- /api/session/properties
- /api/session