QID 731065

Date Published: 2024-01-18

QID 731065: QNAP QTS OS Command Injection Vulnerability (QSA-23-24)

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute commands via a network.

Affected Versions:
QNAP QTS version 5.0.0.1716 build 20210701 prior to version 5.0.1.2376 build 20230421

QID Detection Logic:
This QID checks for vulnerable version of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.

Note: This QID supports only QNAP QTS Devices.

Successful exploitation of the vulnerability may allow an unauthenticated remote attacker to execute arbitrary commands.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as Critical - 9.7 severity.
  • Solution
    Vendor has released patch addressing the vulnerability. Customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-23-24

    Vendor References

    CVEs related to QID 731065

    Software Advisories
    Advisory ID Software Component Link
    QSA-23-24 URL Logo www.qnap.com/en/security-advisory/qsa-23-24