CVE-2024-22900

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
02/02/2024
Last modified:
04/11/2025

Description

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vinchin:vinchin_backup_and_recovery:*:*:*:*:*:*:*:* 7.2 (including)