QID 731065
Date Published: 2024-01-18
QID 731065: QNAP QTS OS Command Injection Vulnerability (QSA-23-24)
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute commands via a network.
Affected Versions:
QNAP QTS version 5.0.0.1716 build 20210701 prior to version 5.0.1.2376 build 20230421
QID Detection Logic:
This QID checks for vulnerable version of QNAP QTS target by sending a GET request to 'authLogin.cgi' endpoint.
Note: This QID supports only QNAP QTS Devices.
Successful exploitation of the vulnerability may allow an unauthenticated remote attacker to execute arbitrary commands.
Solution
Vendor has released patch addressing the vulnerability. Customers are advised to upgrade to the latest version of QNAP QTS. For more information please refer to QSA-23-24
Vendor References
- QSA-23-24 -
www.qnap.com/en/security-advisory/qsa-23-24
CVEs related to QID 731065
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| QSA-23-24 |
|