CVE-2024-55210: Totvs Framework (linha Protheus)

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.

Affected products

  • Totvs Framework (linha Protheus): version 12.1.2310 only

Published 2025-04-09. Last modified 2026-06-17.