CVE-2024-48248: NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

High severity, CVSS 8.6. Actively exploited: in CISA KEV since 2025-03-19. EPSS: 94.4% chance of exploitation in the next 30 days.

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

Affected products

  • NAKIVO Backup & Replication Director: before 11.0.0.88174 (fixed in 11.0.0.88174)

Published 2025-03-04. Last modified 2026-09-24.