Skip to main content

Vendor archive

vinchin CVEs

Beta · best-effort

9 CVEs tagged to vendor vinchin5 Critical, 4 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2024-25228

Published Mar 14, 2024

Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22903

Published Feb 2, 2024

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

CVSS 8.8 · High
Buzz score
6.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-22902

Published Feb 2, 2024

Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.

CVSS 9.8 · Critical
Buzz score
6.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-22900

Published Feb 2, 2024

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.

CVSS 8.8 · High
Buzz score
6.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-22899

Published Feb 2, 2024

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

CVSS 8.8 · High
Buzz score
6.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2022-35866

Published Aug 3, 2022

This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1