📦 Vinchin Backup And Recovery

by Vinchin

🔍 What is Vinchin Backup And Recovery?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-22901

CRITICAL CVSS 9.8 Feb 2, 2024

Vinchin Backup & Recovery v7.2 uses default MySQL credentials (root/vinchin) that allow attackers to gain database access. This can lead to full system compromise through privilege escalation and remo...

CVE-2023-45498

CRITICAL CVSS 9.8 Oct 27, 2023

CVE-2023-45498 is a command injection vulnerability in VinChin Backup & Recovery software that allows attackers to execute arbitrary commands on affected systems. This affects versions 5.0.*, 6.0.*, 6...

CVE-2024-25228

HIGH CVSS 8.8 Mar 14, 2024

This vulnerability allows authenticated attackers to execute arbitrary code on Vinchin Backup and Recovery systems via improper input validation in the getVerifydiyResult function. Attackers with vali...

CVE-2024-22900

HIGH CVSS 8.8 Feb 2, 2024

Vinchin Backup & Recovery v7.2 contains an authenticated remote code execution vulnerability in the setNetworkCardInfo function. This allows authenticated attackers to execute arbitrary commands on th...

CVE-2024-22903

HIGH CVSS 8.8 Feb 2, 2024

Vinchin Backup & Recovery v7.2 contains an authenticated remote code execution vulnerability in the deleteUpdateAPK function. This allows authenticated attackers to execute arbitrary commands on the s...