CVE-2024-55466: Thingsboard

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via uploading a crafted file.

Affected products

Published 2025-05-12. Last modified 2026-06-17.