All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the "external program" feature in the web user interface. This was reportedly exploited in the wild in March 2023.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: VulnCheck

Published: 2023-10-10T13:46:46.775Z

Updated: 2023-10-10T13:46:46.775Z

Reserved: 2023-04-18T10:31:45.962Z


Link: CVE-2023-30801

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-10-10T14:15:10.493

Modified: 2023-11-30T04:15:07.420


Link: CVE-2023-30801

JSON object: View

cve-icon Redhat Information

No data.