Junglewise Threat Intelligence

CVE-2024-44599: FNT Software FNT Command directory traversal via file upload

CVE-2024-44599 · Severity: high · CVSS 8.3 · Published 2025-12-15

Executive brief

FNT Command, a software suite used for managing IT and telecommunications infrastructure, contains a security flaw in its file upload process. An authorized user can bypass security restrictions to place files in unauthorized locations on the server. This could allow an attacker to overwrite critical system files or upload malicious software, potentially leading to a full takeover of the management system and disruption of operations.

Technical details

FNT Command is vulnerable to a directory traversal flaw (CWE-434/CWE-22) within its file upload functionality. The application fails to sufficiently validate or sanitize user-supplied filenames and paths during the upload process. An authenticated attacker with low privileges can exploit this by providing manipulated paths (e.g., using dot-dot-slash sequences) to write arbitrary files outside of the intended upload directory. Depending on the server configuration, this can be leveraged to overwrite configuration files or upload executable scripts to achieve Remote Code Execution (RCE). The issue is resolved in version 13.4.1.

Affected products

  • FNT Software Command Versions up to (excluding) 13.4.1

Timeline

  • 2024-09: disclosed: Vulnerability reported to vendor
  • 2024-10: patched: Vendor published a fix for the issue
  • 2025-12-15: advisory: NVD publication date

References

Related threats