Vulnerabilities & Exploits

Metasploit Modules Turn Old CVEs Into Routine Targets

Public exploit modules change the risk from theoretical to repeatable. Once a flaw lands in Metasploit, unpatched systems stop being obscure findings and become low-effort targets for opportunistic attackers. That is the real shift here, not the CVE announcements themselves.

Rapid7 added modules for Marvell QConvergeConsole CVE-2025-6793, GestioIP 3.5.7 CVE-2024-48760, and Dolibarr ERP/CRM CVE-2023-30253. The GestioIP issue is an authenticated unsafe upload handler flaw that can be pushed into remote code execution, and the QConvergeConsole module reads arbitrary files from versions 5.5.0.85 and earlier.

The new Vim plugin persistence technique widens the story beyond single-product bugs. It gives defenders another reason to watch Unix workstations and developer systems, because persistence can now be hidden in a normal editor plugin path.

1 source · May 15

CVE-2023-30253

NVD KEV

CVSS 8.8 HIGH: dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP… EPSS 82% (100th percentile).

CVE-2024-48760

NVD KEV

CVSS 9.8 CRITICAL: an issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. EPSS 45% (99th percentile).

CVE-2025-6793

NVD KEV

CVSS 9.4 CRITICAL: marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability. EPSS 17% (97th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-16

Every edition of this story: Metasploit Modules Turn Old CVEs Into Routine Targets

More from today