CVE-2024-52564

✓ Confirmed 0-Day
Triaged: March 17, 2026 2 articles

EPSS Score

Source: FIRST.org · 2026-05-24
0.14%
probability
This CVE has a 0.14% probability of being exploited in the next 30 days.
0% Top 33.3th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Signal Intelligence

Confidence
72%
EPSS 0.14%
Mentions 2
Last Seen Dec 04, 2024

CNA Information

Analyst Note

CVE-2024-52564 is a confirmed zero-day. I-O Data and JPCERT/CC disclosed active exploitation in the wild at the time of public disclosure on December 5, 2024 — before a full patch set was available. The vendor confirmed receiving reports from customers whose devices had been compromised without authorization. What makes this CVE analytically distinctive is its root cause: an undocumented feature (CWE-1242), commonly referred to as a firmware backdoor, that bypasses authentication entirely to allow remote firewall deactivation and OS command execution.

Threat Actors 1

MirrorFace
apt_group 🇨🇳 CN

Triage Info

Decided atMar 17, 2026