vendor:
qBittorrent
by:
Jordan Sharp
6.1
CVSS
HIGH
Remote Code Execution (RCE)
284
CWE
Product Name: qBittorrent
Affected Version From: Below 5.0.1
Affected Version To: 5.0.1
Patch Exists: NO
Related CWE: CVE-2024-51774
CPE: a:qbittorrent_foundation:qbittorrent:5.0.0
Platforms Tested: Windows 10
2025
qBittorrent 5.0.1 MITM Remote Code Execution
The exploit allows an attacker to perform Remote Code Execution on qBittorrent version 5.0.1 and below by intercepting the host machine using a Man-In-The-Middle (MITM) attack. By running the Proof of Concept (PoC) exploit, the attacker can inject any malicious executable instead of the legitimate Python installer.
Mitigation:
To mitigate this vulnerability, users should update qBittorrent to version 5.0.1 or above and avoid connecting to untrusted networks where MITM attacks can be performed.