CVE-2024-22902
Critical · CVSS 9.8Vinchin Backup & Recovery — Default Root Credentials
- CVSS
- 9.8
- nvd
- EPSS
- 1.15%
- 63th pct
- KEV
- No
- Class
- other
- NVD-CWE-Other
Description
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
Search profile — drives PoC discovery
Symbols rootdefault credentialsvinchinbackuprecovery
Keywords CVE-2024-22902Vinchin Backup Recoverydefault root credentialsVinchin 7.2Vinchin RCE chainVinchin default password
Versions: v7.2
Ranked PoCs (4) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 0
- ★ 0kaif9711/Strengthened-Security-on-Metasploitable-3 needs reviewtrickest
- ★ 0kaif9711/metasploitable3-vulnerability-assessment needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://blog.leakix.net/2024/01/vinchin-backup-rce-chain/
- https://seclists.org/fulldisclosure/2024/Jan/31
- http://default.com
- http://packetstormsecurity.com/files/176795/Vinchin-Backup-And-Recovery-7.2-Default-Root-Credentials.html
- http://seclists.org/fulldisclosure/2024/Jan/31
- http://vinchin.com
- https://blog.leakix.net/2024/01/vinchin-backup-rce-chain/
- https://seclists.org/fulldisclosure/2024/Jan/31
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z