← Vulnerability feed

Vulnerability record · CVE-2022-24562 · published 16 June 2022

CVE-2022-24562: IOBit IOTransfer Airserv missing authentication allows remote file access and RCE

Iobit · Iotransfer

IOBit IOTransfer 4.3.1.1561 exposes an Airserv service that accepts GET and POST requests without authentication. An unauthenticated attacker can use it to read and write the entire file system with admin privileges, leading to data theft and remote code execution.

9.8 CVSS 3.1 Critical EPSS 54% · top 1.0% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 10.0
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
9 Jul 2026Last modified by NVD

Description

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, full confidentiality, integrity and availability impact, and public exploit references make this a critical exposure for any host running the affected IOTransfer build.

What it is

IOBit IOTransfer 4.3.1.1561 exposes an Airserv service that accepts GET and POST requests without authentication. An unauthenticated attacker can use it to read and write the entire file system with admin privileges, leading to data theft and remote code execution.

Impact

An attacker gains arbitrary read/write access to the victim endpoint's file system at admin privilege level, enabling data theft and remote code execution on the host.

Attack surface

Reachable over the network via the Airserv HTTP interface using GET and POST requests; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is high (0.54483, ~99th percentile) and public exploit references exist, including a Packet Storm exploit writeup and a Medium analysis, indicating public exploitation detail is available.

What to do

  • Upgrade IOTransfer to a version later than 4.3.1.1561 if the vendor provides one; verify with IOBit before relying on any specific fixed build.
  • If the Airserv component is not required, disable or block it and stop the IOTransfer service on endpoints.
  • Restrict network access to the Airserv port with host firewall rules so only trusted management hosts can reach it.
  • Run IOTransfer with the least privilege possible rather than admin rights to limit the impact of file-system access.
  • Monitor for unexpected inbound connections to IOTransfer/Airserv ports and treat any exposure as a compromise indicator.

Detection

  • Monitor network traffic for GET/POST requests to the IOTransfer Airserv service from untrusted hosts.
  • Alert on IOTransfer processes spawning child processes such as cmd.exe or PowerShell, which may indicate RCE.
  • Audit file-system writes and reads by IOTransfer processes outside expected transfer directories.
  • Check endpoint logs for IOTransfer listening on network interfaces where it should not be exposed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24562 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2022-37197Iobit iotransfer unquoted search path vulnerabilityIOBit IOTransfer V4 is vulnerable to Unquoted Service Path.EPSS 1.1%8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed9.3CVE-2026-72529TrueConf Server missing authentication allows remote script executionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier expose an undocumented function on port 4307/TCP …KEVEPSS 1.5%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed9.8CVE-2026-56164Microsoft SharePoint Server missing authentication allows privilege elevationMicrosoft Office SharePoint Server contains a missing authentication flaw in a critical function (CWE-306), letting an unauthenticated attacker reach…KEVEPSS 1.0%analysed9.8CVE-2026-20253Splunk Enterprise PostgreSQL sidecar missing authentication allows file writesSplunk Enterprise 10.2 below 10.2.4 and 10.x below 10.0.7 expose a PostgreSQL sidecar service endpoint that lacks authentication controls. Any networ…KEVEPSS 97%analysed9.8CVE-2026-35273Oracle PeopleSoft PeopleTools missing authentication allows takeoverOracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) in versions 8.61 and 8.62 is missing authentication for a critica…KEVEPSS 9.4%analysed

Source: NIST National Vulnerability Database (record CVE-2022-24562), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.