QID 730968
Date Published: 2023-11-08
QID 730968: QNAP QTS Command Injection Vulnerability (QSA-23-31)
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute commands via a network.
Affected Versions:
QNAP QTS prior to version 5.0.1.2376 build 20230421
QNAP QTS prior to version 4.5.4.2374 build 20230416
QID Detection Logic:
This QID checks for vulnerable version of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.
Note: This QID supports only QNAP QTS Devices.
Successful exploitation of the vulnerability may allow an unauthenticated remote attacker to execute arbitrary commands.
Solution
Vendor has released patch addressing the vulnerability, customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-23-31
Vendor References
- QSA-23-31 -
www.qnap.com/en-uk/security-advisory/qsa-23-31
CVEs related to QID 730968
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| QSA-23-31 |
|