CVE-2023-30801 affects all versions of the qBittorrent client through 4.5.5, stemming from the use of default credentials for its web user interface, which administrators are not forced to change. This critical vulnerability (CVSS 9.8) allows a remote attacker to authenticate without prior knowledge and execute arbitrary operating system commands via the "external program" feature. While no public exploit intelligence is available, this flaw was reportedly exploited in the wild in March 2023, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.5.5CPE matchmatch criteria | cpe:2.3:a:qbittorrent:qbittorrent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.