Vulnerability record · CVE-2024-48766 · published 13 May 2025
CVE-2024-48766: NetAlertX unauthenticated file read via path traversal in logs.php
Netalertx · Netalertx
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading through components/logs.php. An HTTP client can ignore a redirect and combine strpos weaknesses with directory traversal to reach files outside the intended directory. The flaw was exploited in the wild in May 2025, so internet-facing instances are at immediate risk.
Description
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file read with confirmed in-the-wild exploitation and a public exploit module, but not listed in CISA KEV.
What it is
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading through components/logs.php. An HTTP client can ignore a redirect and combine strpos weaknesses with directory traversal to reach files outside the intended directory. The flaw was exploited in the wild in May 2025, so internet-facing instances are at immediate risk.
Impact
An attacker can read arbitrary files on the server without credentials, exposing configuration, credentials, logs and other sensitive data. The CVSS scope change (S:C) indicates the compromise can extend beyond the vulnerable component.
Attack surface
Reachable over the network via HTTP against components/logs.php; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Exploited in the wild in May 2025 and a public Metasploit module exists; EPSS is 0.697 (99.3rd percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade NetAlertX to 24.10.12 or later immediately.
- If patching is delayed, restrict network access to the NetAlertX web interface to trusted hosts only.
- Do not expose the NetAlertX HTTP service directly to the internet; place it behind an authenticating reverse proxy.
- Review the vendor and Rapid7 advisories for interim mitigations and configuration hardening.
- Rotate any credentials or secrets stored in files that may have been exposed.
Detection
- Search web logs for requests to components/logs.php containing traversal sequences such as ../ or encoded variants.
- Alert on requests to components/logs.php that do not follow the expected redirect chain or that return 200 with file content.
- Monitor for Metasploit scanner traffic matching the netalertx_file_read module pattern.
- Audit file access on the NetAlertX host for reads of sensitive paths outside the application directory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/scanner/http/netalertx_file_read. | Exploit |
| https://rhinosecuritylabs.com/research/cve-2024-46506-rce-in-netalertx/ | ExploitMitigationThird Party Advisory |
| https://rhinosecuritylabs.com/research/cve-2024-46506-rce-in-netalertx/ | ExploitMitigationThird Party Advisory |
Track CVE-2024-48766 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-48766), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.