← Vulnerability feed

Vulnerability record · CVE-2024-48766 · published 13 May 2025

CVE-2024-48766: NetAlertX unauthenticated file read via path traversal in logs.php

Netalertx · Netalertx

NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading through components/logs.php. An HTTP client can ignore a redirect and combine strpos weaknesses with directory traversal to reach files outside the intended directory. The flaw was exploited in the wild in May 2025, so internet-facing instances are at immediate risk.

8.6 CVSS 3.1 High EPSS 70% · top 0.7% CWE-698 · CWE-698CWE-22 · Path traversal
8.6CVSS 3.1 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 3 tagged exploit
17 Jun 2026Last modified by NVD

Description

NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote file read with confirmed in-the-wild exploitation and a public exploit module, but not listed in CISA KEV.

What it is

NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading through components/logs.php. An HTTP client can ignore a redirect and combine strpos weaknesses with directory traversal to reach files outside the intended directory. The flaw was exploited in the wild in May 2025, so internet-facing instances are at immediate risk.

Impact

An attacker can read arbitrary files on the server without credentials, exposing configuration, credentials, logs and other sensitive data. The CVSS scope change (S:C) indicates the compromise can extend beyond the vulnerable component.

Attack surface

Reachable over the network via HTTP against components/logs.php; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Exploited in the wild in May 2025 and a public Metasploit module exists; EPSS is 0.697 (99.3rd percentile), though the CVE is not listed in CISA KEV.

What to do

  • Upgrade NetAlertX to 24.10.12 or later immediately.
  • If patching is delayed, restrict network access to the NetAlertX web interface to trusted hosts only.
  • Do not expose the NetAlertX HTTP service directly to the internet; place it behind an authenticating reverse proxy.
  • Review the vendor and Rapid7 advisories for interim mitigations and configuration hardening.
  • Rotate any credentials or secrets stored in files that may have been exposed.

Detection

  • Search web logs for requests to components/logs.php containing traversal sequences such as ../ or encoded variants.
  • Alert on requests to components/logs.php that do not follow the expected redirect chain or that return 200 with file content.
  • Monitor for Metasploit scanner traffic matching the netalertx_file_read module pattern.
  • Audit file access on the NetAlertX host for reads of sensitive paths outside the application directory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-48766 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2024-48766), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.