CVE-2024-34453: LM21 Twonav

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity_test (which reaches /system/api.php).

Affected products

  • LM21 Twonav: version 2.1.13-20240321 only

Published 2024-05-03. Last modified 2026-06-17.