Medium severity6.5NVD Advisory· Published May 12, 2025· Updated Jun 17, 2026
CVE-2024-55466
CVE-2024-55466
Description
An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via uploading a crafted file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:thingsboard:thingsboard:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:thingsboard:thingsboard:*:*:*:*:*:*:*:*range: <=3.8.1
- (no CPE)range: =3.8.1
- ThingsBoard/ThingsBoard Communitydescription
- Range: =3.8.1
Patches
Vulnerability mechanics
References
1- github.com/thingsboard/thingsboard/releases/tag/v3.8.1nvdRelease Notes
News mentions
0No linked articles in our index yet.