The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-39309 The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Fixes

Solution

No solution given by the vendor.


Workaround

TEM has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of the affected products are encouraged to contact TEM https://www.tem-italy.it/en/contacts/  for additional information.

History

Thu, 03 Oct 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Oct 2024 17:45:00 +0000

Type Values Removed Values Added
Description The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Title Cross-Site Request Forgery (CSRF) vulnerability in TEM Opera Plus FM Family Transmitter
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-10-03T18:49:33.596Z

Reserved: 2024-07-25T16:53:53.053Z

Link: CVE-2024-41987

cve-icon Vulnrichment

Updated: 2024-10-03T18:49:29.843Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-03T18:15:04.837

Modified: 2024-10-04T13:50:43.727

Link: CVE-2024-41987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:00:47Z