Two vulnerabilities in the GPS tracking system, Traccar, could be exploited by unauthorized attackers to execute code remotely under certain circumstances.

The two vulnerabilities are related to “path traversal weaknesses” and could be exploited when guest registration is enabled. Unfortunately, this is the default configuration for Traccar 5, according to Horizon3.ai researcher Naveen Sunkavally.
The two vulnerabilities are as follows:
CVE-2024-24809 (CVSS score: 8.5) – Path Traversal: 'dir/../../filename' and uploading potentially dangerous files
CVE-2024-31214 (CVSS score: 9.7) – Vulnerability that could lead to remote code execution
See also: SolarWinds: Fixes Critical Vulnerability in Web Help Desk
According to Sunkavally, successful exploitation of the CVE-2024-31214 and CVE-2024-24809 vulnerabilities in Traccar allows an attacker to place files with any (even dangerous) content anywhere on the file system.
“However, an attacker only has partial control over the filename“.
The security issues have to do with how the GPS program handles device image file uploads, essentially allowing an attacker to replace certain files in the file system and trigger code execution.
Files that match the following naming format are included:
- device.ext, where the attacker can control ext, but there MUST be an extension
- blah”, where the attacker can check blah, but the filename must end with double quotes
- blah1″;blah2=blah3, where the attacker can check blah1, blah2 and blah3, but the sequence of question mark, double quotes and equal sign MUST be present
See also: GitHub: GHES vulnerability allows authentication bypass
In a hypothetical proof-of-concept (PoC) exploit devised by Horizon3.ai, an attacker can exploit path traversal in the Content-Type header to upload a crontab file and obtain a reverse shell on the attacker's host.

This attack method, however, does not work on Debian/Ubuntu-based Linux systems
An alternative mechanism involves exploiting Traccar, which is installed as a root-level user to install a kernel module or configure a udev rule.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
On Windows systems , remote code execution could also be achieved by placing a shortcut file (LNK) named “device.lnk” in the C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp folder, which is then executed when any victim user logs on to the Traccar host.
Traccar versions 5.1 to 5.12 are vulnerable to two vulnerabilities CVE-2024-31214 and CVE-2024-2809. The issues were addressed in Traccar version 6.
See also: LiteSpeed Cache vulnerability puts millions of WordPress sites at risk
The disclosure of the two vulnerabilities highlights the importance of regular security checks for all software, even for popular and widely used ones like Traccar. It also emphasizes the need for prompt updates and proper management of settings to ensure a safer environment for all users. Organizations should take proactive measures to protect their data and assets, especially when using sensitive systems like tracking . Therefore, it is important to stay informed about potential risks and address them in a timely manner to maintain a safe digital environment. If you use Traccar or any other software, make sure to keep it updated and follow security best practices to better protect against potential threats.
Source: thehackernews.com
