CVE-2023-30801
CVSS v3
9.8
CRITICAL
EPSS Score
1.2 %
exploit probability, as of 2026-10-11
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Affected and fixed versions
Packages from OSV.dev and products from the vendors' CSAF advisories.
version not verifiedVersions not verified: read as OSV.dev and the vendors publish them, not checked against each vendor's release list.
Vendor advisories
- CVE-2023-30801 Red Hat Product Security
qbittorrent: default credentials allowed by default
Description
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the "external program" feature in the web user interface. This was reportedly exploited in the wild in March 2023.
Technical details
- Published
- 2023-10-10
Frequently asked questions
What is CVE-2023-30801?
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the "external program" feature in the web user interface. This was reportedly exploited in the wild in March 2023.
Is CVE-2023-30801 actively exploited?
Active exploitation of CVE-2023-30801 has not been confirmed. Its EPSS score was 1.2% on 2026-10-11, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2023-30801?
CVE-2023-30801 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Running qbittorrent? Hear about its next vulnerability
CVE Watch matches each new CVE to the vendors and products you list (vendor and product, not the version) and puts it in your alerts with its KEV and EPSS status.
Already have an account? Open CVE Watch
No credit card required · 50 free checks/month · Free API key
Go further
- Following what attackers exploit right now? The CISA KEV additions of the month, with their patch deadlines.
- Running this software? CVE Watch alerts you to new vulnerabilities in your products.
Related vulnerabilities
Same product first, then the same vendor advisory and the same publication week.