HomeSecurityTraccar GPS: Vulnerabilities allow remote attacks

GPS Tracker: Vulnerabilities allow remote attacks

Two vulnerabilities in the GPS tracking system, Traccar, could be exploited by unauthorized attackers to execute code remotely under certain circumstances.

GPS tracker vulnerabilities

The two vulnerabilities are related to “path traversal weaknesses” and could be exploited when guest registration is enabled. Unfortunately, this is the default configuration for Traccar 5, according to Horizon3.ai researcher Naveen Sunkavally.

The two vulnerabilities are as follows:

CVE-2024-24809 (CVSS score: 8.5) – Path Traversal: 'dir/../../filename' and uploading potentially dangerous files

CVE-2024-31214 (CVSS score: 9.7) – Vulnerability that could lead to remote code execution

See also: SolarWinds: Fixes Critical Vulnerability in Web Help Desk

According to Sunkavally, successful exploitation of the CVE-2024-31214 and CVE-2024-24809 vulnerabilities in Traccar allows an attacker to place files with any (even dangerous) content anywhere on the file system.

 “However, an attacker only has partial control over the filename“.

The security issues have to do with how the GPS program handles device image file uploads, essentially allowing an attacker to replace certain files in the file system and trigger code execution.

Files that match the following naming format are included:

  • device.ext, where the attacker can control ext, but there MUST be an extension
  • blah”, where the attacker can check blah, but the filename must end with double quotes
  • blah1″;blah2=blah3, where the attacker can check blah1, blah2 and blah3, but the sequence of question mark, double quotes and equal sign MUST be present

See also: GitHub: GHES vulnerability allows authentication bypass

In a hypothetical proof-of-concept (PoC) exploit devised by Horizon3.ai, an attacker can exploit path traversal in the Content-Type header to upload a crontab file and obtain a reverse shell on the attacker's host.

GPS Tracker: Vulnerabilities allow remote attacks

This attack method, however, does not work on Debian/Ubuntu-based Linux systems

An alternative mechanism involves exploiting Traccar, which is installed as a root-level user to install a kernel module or configure a udev rule.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

On Windows systems , remote code execution could also be achieved by placing a shortcut file (LNK) named “device.lnk” in the C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp folder, which is then executed when any victim user logs on to the Traccar host.

Traccar versions 5.1 to 5.12 are vulnerable to two vulnerabilities CVE-2024-31214 and CVE-2024-2809. The issues were addressed in Traccar version 6.

See also: LiteSpeed ​​Cache vulnerability puts millions of WordPress sites at risk

The disclosure of the two vulnerabilities highlights the importance of regular security checks for all software, even for popular and widely used ones like Traccar. It also emphasizes the need for prompt updates and proper management of settings to ensure a safer environment for all users. Organizations should take proactive measures to protect their data and assets, especially when using sensitive systems like tracking . Therefore, it is important to stay informed about potential risks and address them in a timely manner to maintain a safe digital environment. If you use Traccar or any other software, make sure to keep it updated and follow security best practices to better protect against potential threats.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS