CVE-2024-22900: Vinchin Backup And Recovery

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.

Affected products

  • Vinchin Vinchin Backup And Recovery: up to and including 7.2

Published 2024-02-02. Last modified 2026-07-09.