QID 731064

Date Published: 2024-01-17

QID 731064: QNAP QTS Remote Code Injection Vulnerability (QSA-23-01)

QTS is the operating system for all entry-level and mid-level QNAP NAS models.

CVE-2022-27596: Remote code Injection has been reported to affect certain QNAP operating systems.

Affected Versions:
QNAP QTS prior to version 5.0.1.2234 build 20221201.

QID Detection Logic:
This QID checks for vulnerable versions of the QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.

Successful exploitation of the vulnerability may allows remote attackers to inject malicious code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    The vendor has released a patch addressing the vulnerability, customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-23-01
    Vendor References

    CVEs related to QID 731064

    Software Advisories
    Advisory ID Software Component Link
    QSA-23-01 URL Logo www.qnap.com/en/security-advisory/qsa-23-01