Attackers began actively probing NAKIVO Backup & Replication for CVE-2024-48248, an unauthenticated arbitrary file-read vulnerability that was publicly disclosed in September 2024 and later detailed with proof-of-concept research by watchTowr. MBSD-SOC reported first seeing exploitation attempts on 2025-02-27, with activity continuing into March, indicating that the flaw had moved from public disclosure into observed attack traffic against exposed systems.
One observed request targeted the /c/router endpoint with the STPreLoadManagement action and getImageByPath method to retrieve /etc/passwd, a common check used to confirm arbitrary file access on Linux hosts. MBSD-SOC said many of the attack sources it saw were located in France, while NAKIVO release notes indicate fixes are available, prompting defenders to urgently update affected installations to the latest patched version and review internet-exposed backup infrastructure for signs of compromise.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
After first being seen in late February, exploitation activity against vulnerable NAKIVO Backup & Replication systems continued into March 2025. MBSD-SOC said many observed attack sources were located in France.
MBSD-SOC reported first seeing attacks targeting CVE-2024-48248 on this date. One observed attempt used a POST request to "/c/router" with the "STPreLoadManagement" action and "getImageByPath" method to try reading "/etc/passwd".
The arbitrary file-read vulnerability CVE-2024-48248 in NAKIVO Backup & Replication was publicly disclosed. The flaw can allow unauthenticated attackers to read arbitrary files if exploited.
Public proof-of-concept exploit code for CVE-2024-48248 was available by the time of the reporting. This lowered the barrier to exploitation of the NAKIVO flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
mbsd.jp
Open sourcelabs.watchtowr.com
Open sourcehelpcenter.nakivo.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.