CVE-2024-48248

HIGH KEV NUCLEI

NAKIVO Backup & Replication < 11.0.0.88174 - Absolute Path Traversal via getImageByPath

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-48248 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 19, 2025. EIP tracks 2 public exploits from researchers including iSee857, watchtowrlabs. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains functional exploit code for CVE-2024-48248, demonstrating command execution via a session-based shell endpoint in OpenCode. The script includes multi-threaded scanning capabilities and payload delivery for RCE.

Description

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

Exploits (2)

github WORKING POC 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/NAKIVO_CVE-2024-48248_ReadAnyFile.py

The repository contains functional exploit code for CVE-2024-48248, demonstrating command execution via a session-based shell endpoint in OpenCode. The script includes multi-threaded scanning capabilities and payload delivery for RCE.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: OpenCode (version not specified)
No auth needed
Prerequisites: network access to target · OpenCode instance with vulnerable endpoint
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC 3 stars
by watchtowrlabs · infoleak
https://github.com/watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-48248

This is a functional proof-of-concept exploit for CVE-2024-48248, demonstrating unauthenticated arbitrary file read in NAKIVO Backup and Replication Solution. The script sends a crafted JSON payload to the target endpoint to retrieve file contents.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: NAKIVO Backup and Replication Solution 10.11.3.86570 and below
No auth needed
Prerequisites: Network access to the target NAKIVO instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

NAKIVO Backup and Replication Solution - Unauthenticated Arbitrary File Read
HIGHVERIFIEDby DhiyaneshDK
Shodan: title:"NAKIVO"
FOFA: title="NAKIVO"

Scores

CVSS v3 8.6
EPSS 0.9401
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2025-03-19
VulnCheck KEV 2025-03-16
ENISA EUVD EUVD-2024-54120
CWE
CWE-36
Status published
Products (1)
nakivo/backup_\&_replication_director < 11.0.0.88174
Published Mar 04, 2025
KEV Added Mar 19, 2025
Tracked Since Feb 18, 2026