CRITICAL🇵🇱 Wersja polska

CVE-2024-7746

CVSS 9.5v4.0pub. 2024-08-13upd. 2024-08-22

Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwise be protected by the authentication mechanism.  These transactions could have an impact on any sensitive aspect of the platform, including Confidentiality, Integrity and Availability.

🤖 AI Analysis
How it works

The Traccar Server application has default login credentials pre-configured (CWE-1392) that are not forced to change during deployment. An attacker can use these known credentials to gain access to privileged administrative panel functions, effectively bypassing the authentication mechanism (CWE-287). The vulnerability affects protected transactions that should only be accessible to authenticated and authorized administrators.

Impact

Attacker gains full access to privileged platform functions, directly violating system confidentiality, integrity, and availability. Complete platform takeover, data manipulation, and disruption of operations are possible.

Mitigation & patch

Default login credentials must be immediately changed to strong, unique passwords for all administrative accounts. Apply patches available from the vendor according to references. Additionally, it is recommended to restrict access to the administrative panel exclusively to trusted IP addresses and conduct regular user account reviews.

Who is affected

Traccar Server (Tananaev Solutions) — versions indicated in vendor references; vulnerability affects the administrative panel module

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Traccar

    APP
    Traccar
    2.12 – 6.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-31214CRITICAL9.6PL ✓same product

Traccar: nieograniczony upload plików prowadzący do RCE

CVE-2026-25649HIGH7.3same product

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which a...

CVE-2026-25648HIGH8.7same product

Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authent...

CVE-2025-68930HIGH7.1same product

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSoc...

CVE-2023-50729HIGH8.4same product

Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file uplo...