CVE-2024-48862

CRITICAL

A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or...

Affects 1 product across 1 vendor.

BCS7.51
CVSS 3.19.8
CVSS v48.7
EPSS0.9%
Percentile58th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-59: Improper Link Resolution Before File Access

Software follows symbolic links without verifying the target, allowing read, write, or delete of unintended files.

Related Attack Patterns (CAPEC)
CAPEC-35 Leverage Executable Code in Non-Executable Files
via CWE-59
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-59
CAPEC-132 Symlink Attack
via CWE-59
CAPEC-17 Using Malicious Files
via CWE-59

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A link following vulnerability in QuLog Center could allow remote attackers to traverse the file system and access or modify files. The vulnerability affects versions prior to 1.7.0.831 and 1.8.0.888.

BSID: BS-2024-GLOBAL-216374-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-48862?
A link following vulnerability in QuLog Center could allow remote attackers to traverse the file system and access or modify files. The vulnerability affects versions prior to 1.7.0.831 and 1.8.0.888.
What is the CVSS score for CVE-2024-48862?
CVE-2024-48862 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.9%.
Is CVE-2024-48862 actively exploited?
No confirmed active exploitation of CVE-2024-48862 as of 2026-05-30.
How do I remediate CVE-2024-48862?
Priority: IMMEDIATE. Advisory: https://www.qnap.com/en/security-advisory/qsa-24-46 PSIRT: [email protected]
What systems are affected by CVE-2024-48862?
CVE-2024-48862 affects: Qnap.
Vulnerability Details
CVE IDCVE-2024-48862
BSIDBS-2024-GLOBAL-216374-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2024-11-22
Last Modified2025-12-08
ICS Relevance70%
Weakness (CWE)
SourceNVD
Official Description

A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.831 ( 2024/10/15 ) and later QuLog Center 1.8.0.888 ( 2024/10/15 ) and later

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited by tricking the application into following a malicious link, which can lead to unauthorized file system access.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Qnap Qulog Center
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 632 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash38462c001b9b893e9b423093bd726b36bda2dea54594806c2320f2c115f926c01801c860bb223552cb22742e763ad8a8ec021c34590b5cbbca070e2d00e389fb
Related CVEs affecting Qnap
CVE-2017-7876 10.0 This command injection vulnerability in QTS allows attackers to run arbitrary... CVE-2024-32766 10.0 An OS command injection vulnerability has been reported to affect several QNA... CVE-2024-32764 9.9 A missing authentication for critical function vulnerability has been reporte... CVE-2024-21899 9.8 An improper authentication vulnerability has been reported to affect several ... CVE-2024-48863 9.8 A command injection vulnerability has been reported to affect License Center....
View all Qnap CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →