Vulnerability record · CVE-2024-48248 · published 4 March 2025
CVE-2024-48248: NAKIVO Backup & Replication absolute path traversal file read
Nakivo · Backup \& Replication Director
NAKIVO Backup & Replication before 11.0.0.88174 exposes the getImageByPath endpoint at /c/router, which fails to restrict file paths and allows absolute path traversal to read arbitrary files. Because PhysicalDiscovery stores cleartext credentials, reading those files can hand an attacker the credentials needed to move laterally and execute code across the enterprise.
Description
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with a near-maximum EPSS score, requires no authentication, and can expose cleartext credentials that enable enterprise-wide compromise.
What it is
NAKIVO Backup & Replication before 11.0.0.88174 exposes the getImageByPath endpoint at /c/router, which fails to restrict file paths and allows absolute path traversal to read arbitrary files. Because PhysicalDiscovery stores cleartext credentials, reading those files can hand an attacker the credentials needed to move laterally and execute code across the enterprise.
Impact
An unauthenticated attacker can read arbitrary files from the appliance, including configuration and credential material. Those cleartext PhysicalDiscovery credentials can be reused to compromise other enterprise systems, potentially leading to remote code execution.
Attack surface
Reached over the network via the /c/router endpoint using getImageByPath; the CVSS vector shows no privileges or user interaction required. Any host that can reach the NAKIVO service can attempt the traversal.
Exploitation
CISA added this to KEV on 2025-03-19 with a 2025-04-09 remediation due date, and EPSS is 0.94356 (99.8th percentile), indicating active exploitation. A public proof-of-concept exploit is referenced by WatchTowr.
What to do
- Upgrade NAKIVO Backup & Replication to 11.0.0.88174 or later immediately.
- If patching is not possible, isolate the NAKIVO appliance from untrusted networks and restrict access to the management interface.
- Rotate any credentials stored or used by PhysicalDiscovery and other NAKIVO components, since cleartext credentials may have been exposed.
- Follow CISA BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable.
Detection
- Monitor HTTP requests to /c/router with getImageByPath parameters containing absolute paths or traversal sequences.
- Alert on unexpected outbound connections or authentication attempts from the NAKIVO appliance using stored credentials.
- Review file access logs on the appliance for reads of configuration or credential files outside expected paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-48248 to the Known Exploited Vulnerabilities catalog on 19 March 2025 as "NAKIVO Backup and Replication Absolute Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 9 April 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-48248 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-48248), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.