CVE-2024-47088: Apexsoftcell Ld Dp Back Office

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on login OTP, which could lead to gain unauthorized access to other user accounts.

Affected products

  • Apexsoftcell Ld Dp Back Office: before 24.8.21.1 (fixed in 24.8.21.1)
  • Apexsoftcell Ld Geo: before 4.0.0.7 (fixed in 4.0.0.7)

Published 2024-09-19. Last modified 2026-06-17.