CVSS v3
8.6
HIGH
EPSS Score
77.7%
exploit probability
CISA KEV
No
known exploited
Exploitation
poc
SSVC status
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.
A proof-of-concept exploit exists for CVE-2024-48766, but active exploitation has not been confirmed at this time.
CVE-2024-48766 has a CVSS v3 base score of 8.6 (HIGH severity), with vector string 3.1.
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).