CVE-2024-48766 is a critical unauthenticated file reading vulnerability affecting NetAlertX versions prior to 24.10.12. This flaw, stemming from improper handling of HTTP redirects combined with directory traversal (CWE-22) and an issue related to strpos (CWE-698) in components/logs.php, allows attackers to read arbitrary files. With a CVSS score of 8.6 (High), it presents a severe risk due to its network-based attack vector, low attack complexity, and high confidentiality impact. The vulnerability has been actively exploited in the wild since May 2025, with public exploit code available via Metasploit and Nuclei templates, and has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 24.7.18, < 24.10.12CPE matchmatch criteria | cpe:2.3:a:netalertx:netalertx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.