CVE-2022-24562
Critical · CVSS 9.8IOBit IOTransfer — Unauthenticated arbitrary file read/write via missing authentication on Airserv API (CWE-306)
- CVSS
- 9.8
- nvd
- EPSS
- 53.9%
- 99th pct
- KEV
- No
- Class
- other
- CWE-306
Description
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.
Search profile — drives PoC discovery
Symbols AirservIOTransferGETPOSTunauthenticatedfile-systemadmin privilegesinsecure API
Keywords CVE-2022-24562IOTransferIOBitAirservunauthenticated RCEarbitrary file read writemissing authenticationIOTransfer exploitIOTransfer PoCIOTransfer 4.3.1.1561
Versions: 4.3.1.1561 (also referenced as 4.0)
Ranked PoCs (2) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 0zhanpengliu-tencent/medium-cve needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- http://packetstormsecurity.com/files/167775/IOTransfer-4.0-Remote-Code-Execution.html
- https://medium.com/@tomerp_77017/exploiting-iotransfer-insecure-api-cve-2022-24562-a2c4a3f9149d
- http://iobit.com
- http://iotransfer.com
- http://packetstormsecurity.com/files/167775/IOTransfer-4.0-Remote-Code-Execution.html
- https://medium.com/%40tomerp_77017/exploiting-iotransfer-insecure-api-cve-2022-24562-a2c4a3f9149d
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z