TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains a Relative Path Traversal vulnerability, allowing attackers to write arbitrary files to any path on the user's system.
History

Tue, 23 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Cht
Cht tenderdoctransfer
CPEs cpe:2.3:a:cht:tenderdoctransfer:*:*:*:*:*:*:*:*
Vendors & Products Cht
Cht tenderdoctransfer

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00121}

epss

{'score': 0.0013}


Mon, 16 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Dec 2024 06:45:00 +0000

Type Values Removed Values Added
Description TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains a Relative Path Traversal vulnerability, allowing attackers to write arbitrary files to any path on the user's system.
Title Chunghwa Telecom TenderDocTransfer - Arbitrary File Write
Weaknesses CWE-23
CWE-352
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-12-16T16:43:44.651Z

Reserved: 2024-12-16T01:39:22.535Z

Link: CVE-2024-12642

cve-icon Vulnrichment

Updated: 2024-12-16T16:43:41.059Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-16T07:15:06.023

Modified: 2025-12-23T19:53:25.663

Link: CVE-2024-12642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.