TREK versions prior to 2.7.2 contain an authentication bypass vulnerability that allows unauthenticated users to access and download uploaded photos without proper access controls. This issue has been remediated in version 2.7.2, and users should upgrade immediately to eliminate the exposure. The vulnerability presents a medium severity risk with a CVSS score of 5.3, exploitable remotely over the network with low attack complexity and no user interaction required. The primary impact is integrity-related, though the overall threat is mitigated by the lack of confidentiality or availability impacts. The EPSS score of 0.0006 indicates a very low probability of exploitation in the wild relative to other vulnerabilities. There is no evidence of active exploitation, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat monitoring lists. Community attention appears minimal, suggesting limited public awareness or exploit code availability. Organizations should prioritize patching based on the presence of TREK in their environment rather than current exploitation pressure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.7.1CPE matchmatch criteria | cpe:2.3:a:mauriceboe:trek:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.