CVE-2024-24809 is a critical vulnerability in Traccar versions 5.1 to 5.12, an open source GPS tracking system. The vulnerability arises from improper validation in the device image upload API, allowing attackers to perform path traversal and upload files with dangerous types to arbitrary locations on the server filesystem. Since guest registration is enabled by default, unauthenticated attackers can register accounts and exploit this flaw to upload files with the prefix 'device.' under any folder, leading to remote code execution on both Linux and Windows systems. The vulnerability was reported by Horizon3.ai and @yiliufeng168 and is patched in Traccar 6.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting Palo Alto Expedition (version 1.2.91 and below) for remote code execution via two vulnerabilities: CVE-2024-5910 (admin password reset) and CVE-2024-9464 (authenticated OS command injection). The module can exploit the command injection directly if valid credentials are provided, or it can first reset the admin password to the default and then proceed. The exploit interacts with the Expedition web interface over HTTPS, using endpoints such as /bin/Auth.php for authentication, /OS/startup/restore/restoreAdmin.php for password reset, and /bin/CronJobs.php for command injection. The payload is a staged shell command, typically used to gain a shell as the www-data user. The code is written in Ruby and is structured as a standard Metasploit exploit module, making it weaponized and easily customizable for attackers.
This repository contains a single Metasploit module (modules/exploits/linux/http/traccar_rce_upload.rb) that exploits two vulnerabilities (CVE-2024-31214 and CVE-2024-24809) in Traccar v5.1-v5.12. The exploit works by first registering a new user (or authenticating as an existing one), creating a device, and then abusing the device image upload endpoint to perform a path traversal and upload a malicious cron job to /etc/cron.d/. This cron job executes attacker-supplied commands as root, leading to full remote code execution. The module is weaponized, supporting arbitrary command payloads (including reverse shells) and is designed for Red Hat-based Linux systems. The main attack vector is network-based, targeting the Traccar web interface (default port 8082). The code is well-structured, with clear separation of setup, authentication, and exploitation steps, and leverages Metasploit's HttpClient and FileDropper mixins for HTTP requests and cleanup.
This repository provides an exploit for CVE-2024-24809, an authentication bypass and arbitrary file upload vulnerability in Traccar GPS tracking system versions prior to 6.0. The repository contains three files: a Nuclei template (CVE-2024-24809.yaml), a Python proof-of-concept exploit (poc.py), and a README.md with usage instructions and vulnerability details. The exploit works by registering a new user (using default registration), logging in, adding a device, and then exploiting a path traversal in the device image upload functionality to place arbitrary files (with a 'device.' prefix) in attacker-chosen locations on the server. The Python script automates this process, and the Nuclei template provides a way to scan for the vulnerability. The main attack vector is network-based, targeting the Traccar HTTP API endpoints. The exploit can be used for phishing, XSS, or potentially remote code execution, depending on the file uploaded and the server configuration. The repository is operational and provides a working exploit, not just a detection script.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.