{"id":"CVE-2022-24562","title":"In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in da…","summary":"In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in da…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-306"],"vendor":"iobit","product":"iotransfer","affected":["iotransfer = 4.3.1.1561"],"published":"2022-06-16","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-24562","references":[{"url":"http://packetstormsecurity.com/files/167775/IOTransfer-4.0-Remote-Code-Execution.html","label":"cve@mitre.org"},{"url":"https://medium.com/@tomerp_77017/exploiting-iotransfer-insecure-api-cve-2022-24562-a2c4a3f9149d","label":"cve@mitre.org"},{"url":"http://iobit.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://iotransfer.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.com/files/167775/IOTransfer-4.0-Remote-Code-Execution.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://medium.com/%40tomerp_77017/exploiting-iotransfer-insecure-api-cve-2022-24562-a2c4a3f9149d","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.54483,"epssPercentile":0.98966,"exploitAvailable":true,"ingestedAt":"2026-07-06T17:03:24.426Z","exploits":{"exploitdb":true,"checkedAt":"2026-09-23T07:13:22.877Z"},"slug":"CVE-2022-24562","body":"## Overview\n\nIn IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.\n\n## Affected\n\n- `iotransfer = 4.3.1.1561`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":77,"depthScoreParts":{"impact":53.9,"likelihood":10.9,"exploitation":12,"ransomware":0},"changes":[]}