QID 730968

Date Published: 2023-11-08

QID 730968: QNAP QTS Command Injection Vulnerability (QSA-23-31)

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute commands via a network.

Affected Versions:
QNAP QTS prior to version 5.0.1.2376 build 20230421
QNAP QTS prior to version 4.5.4.2374 build 20230416

QID Detection Logic:
This QID checks for vulnerable version of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.

Note: This QID supports only QNAP QTS Devices.

Successful exploitation of the vulnerability may allow an unauthenticated remote attacker to execute arbitrary commands.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Vendor has released patch addressing the vulnerability, customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-23-31

    CVEs related to QID 730968

    Software Advisories
    Advisory ID Software Component Link
    QSA-23-31 URL Logo www.qnap.com/en-uk/security-advisory/qsa-23-31