CVE-2024-54767 alleges a missing-authentication access-control issue in AVM FRITZ!Box 7530 AX version 7.59 that could expose sensitive information to unauthenticated attackers. The supplier disputes the issue, stating that it cannot be reproduced and that the report concerns an unintended configuration involving direct Internet exposure.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This five-file Python repository is an unauthenticated information-disclosure proof of concept for AVM FRITZ!Box devices, centered on CVE-2024-54767. The documented confirmed target is a FRITZ!Box 7530 AX running FRITZ!OS 7.59, although the README claims related behavior was observed on additional models and versions without assigning vendor-confirmed CVEs. main_exploit.py is the CLI entry point and accepts either IPv4 or IPv6 targets, a custom User-Agent or a randomly selected browser User-Agent, and a choice of requests-based or raw TCP-socket HTTP transport. xml_request.py requests each endpoint through the Python requests library; xml_socket.py manually constructs HTTP/1.1 GET requests and reads raw responses. Both paths contact TCP port 80 and sequentially retrieve /juis_boxinfo.xml, /jason_boxinfo.xml, and /cgi-bin/system_status. user_agents.py supplies randomized browser User-Agent strings. The code does not authenticate, parse or validate response content, check HTTP status codes, or distinguish genuine disclosure from ordinary/error responses; it appends and prints any received response body. It is therefore an active exploitation/verification tool rather than a passive detection-only script, but contains no execution payload or post-exploitation capability.
This four-file Python proof-of-concept targets AVM FRITZ!Box devices and identifies CVE-2024-54767 in comments. `main_exploit.py` is the CLI entry point: it requires a target IPv4 or IPv6 address, a request mode (`--http` or `--socket`), and either a custom or randomized User-Agent. It always targets TCP port 80. `xml_request.py` uses `requests` to GET `/juis_boxinfo.xml`; `xml_socket.py` implements equivalent HTTP retrieval over a raw TCP socket; and `user_agents.py` supplies randomized browser User-Agent strings. The code has no command-execution, persistence, credential-theft, or reverse-shell payload. Its sole capability is unauthenticated retrieval and display of the XML response. A notable implementation defect is that IPv6 selection is never propagated to the helper functions, so requests will generally be constructed and connected as IPv4 despite accepting `--ipv6` input.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.