Cyber Security News

Multiple QNAP Vulnerabilities Let Remote Attackers To Compromise The System Remotely

QNAP Systems, a leading provider of network-attached storage (NAS) solutions, has disclosed multiple critical vulnerabilities affecting its QTS and QuTS hero operating systems.

The security advisory, released on December 7, 2024, details eight vulnerabilities discovered during the Pwn2Own 2024 competition, potentially allowing remote attackers to compromise system security.

The vulnerabilities, identified as CVE-2024-48859, CVE-2024-48865, CVE-2024-48866, CVE-2024-48867, CVE-2024-48868, CVE-2024-50393, CVE-2024-50402, and CVE-2024-50403.

Besides this, all these above-mentioned vulnerabilities affected the QTS versions 5.1.x and 5.2.x, as well as QuTS hero versions h5.1.x and h5.2.x.

The most severe vulnerability, CVE-2024-48859, is an improper authentication flaw that could allow remote attackers to compromise system security.

However, researchers at QNAP noted another critical issue, which is “CVE-2024-48865,” that involves improper certificate validation, potentially enabling local network attackers to breach system security.

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

Vulnerabilities

  • CVE-2024-48859: Improper authentication flaw
  • CVE-2024-48865: It involves improper certificate validation
  • CVE-2024-48866: Improper handling of URL encoding, allowing remote attackers to cause unexpected system states
  • CVE-2024-48867 and CVE-2024-48868: CRLF injection vulnerabilities, enabling remote attackers to modify application data
  • CVE-2024-50393: A command injection vulnerability, permitting remote attackers to execute arbitrary commands
  • CVE-2024-50402 and CVE-2024-50403: Use of externally-controlled format string vulnerabilities, allowing attackers with administrator access to obtain secret data or modify memory

QNAP has addressed these vulnerabilities in the following versions:-

Affected ProductFixed Version
QTS 5.1.xQTS 5.1.9.2954 build 20241120 and later
QTS 5.2.xQTS 5.2.2.2950 build 20241114 and later
QuTS hero h5.1.xQuTS hero h5.1.9.2954 build 20241120 and later
QuTS hero h5.2.xQuTS hero h5.2.2.2952 build 20241116 and later

To mitigate these risks, QNAP strongly recommends users update their systems to the latest version.

Users can perform updates through the QTS or QuTS hero interface by logging in as an administrator, navigating to Control Panel > System > Firmware Update, and clicking “Check for Update” under Live Update.

This security advisory follows a series of vulnerability disclosures by QNAP in recent months. In November 2024, the company addressed multiple vulnerabilities in QTS and QuTS hero, including buffer overflow and NULL pointer dereference issues.

Earlier in April 2024, a critical vulnerability (CVE-2024-21899) was patched, which could have allowed network attackers to access QNAP NAS devices without authentication.

Given the potential impact of these vulnerabilities and the history of QNAP products being targeted by threat actors, users are urged to apply the updates promptly to ensure the security of their NAS devices and data.

Analyse Real-World Malware & Phishing Attacks With ANY.RUN - Get up to 3 Free Licenses

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago