id: CVE-2024-54767 info: name: AVM FRITZ!Box 7530 AX - Unauthorized Access author: DhiyaneshDK severity: high description: | An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication. impact: | Unauthenticated attackers can access sensitive device information including firmware version, serial numbers, and configuration details through the boxinfo XML endpoint. remediation: | Update AVM FRITZ!Box 7530 AX to a version later than 7.59 that addresses the unauthorized access vulnerability. reference: - https://github.com/Shuanunio/CVE_Requests/blob/main/AVM/fritz/AVM_FRITZ%21Box_7530%20AX_unauthorized_access_vulnerability_first.md classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2024-54767 cwe-id: CWE-203 epss-score: 0.01787 epss-percentile: 0.76028 metadata: verified: true max-request: 1 fofa-query: body="FRITZ!Box 7530" tags: cve,cve2024,fritz!box,info-leak,unauth,vuln http: - raw: - | GET //juis_boxinfo.xml HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word part: body words: - "