Skip to main content
CRITICAL

CVE-2023-30801

CVSS v3

9.8

CRITICAL

EPSS Score

1.2 %

exploit probability, as of 2026-10-11

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Affected and fixed versions

Packages from OSV.dev and products from the vendors' CSAF advisories.

version not verifiedVersions not verified: read as OSV.dev and the vendors publish them, not checked against each vendor's release list.

Vendor advisories

  • CVE-2023-30801 Red Hat Product Security

    qbittorrent: default credentials allowed by default

Full record on NVD

Description

All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the "external program" feature in the web user interface. This was reportedly exploited in the wild in March 2023.

Technical details

Published
2023-10-10

Frequently asked questions

What is CVE-2023-30801?

All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the "external program" feature in the web user interface. This was reportedly exploited in the wild in March 2023.

Is CVE-2023-30801 actively exploited?

Active exploitation of CVE-2023-30801 has not been confirmed. Its EPSS score was 1.2% on 2026-10-11, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-30801?

CVE-2023-30801 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Running qbittorrent? Hear about its next vulnerability

CVE Watch matches each new CVE to the vendors and products you list (vendor and product, not the version) and puts it in your alerts with its KEV and EPSS status.

Already have an account? Open CVE Watch

No credit card required · 50 free checks/month · Free API key