Cyber Security News

QNAP NAS Critical Vulnerability Let Attacker Inject Arbitrary Code

Updates for QNAP’s network-attached storage (NAS) systems have been released to address a critical security flaw that might allow arbitrary code injection.

Customers of QNAP are being advised to update their QTS and QuTS firmware in order to fix a critical security flaw.

The security flaw is tracked as (CVE-2022-27596) and rated as “Critical” (CVSS v3 score: 9.8). It affects the QTS 5.0.1 and QuTS hero h5.0.1 versions of the operating system.

“Vulnerability has been reported to affect QNAP devices running QTS 5.0.1 and QuTS hero h5.0.1. If exploited, this vulnerability allows remote attackers to inject malicious code”, according to the QNAP security advisory.

The NIST National Vulnerability Database (NVD) has identified the flaw as an SQL injection vulnerability despite the fact that the specific technical details around it are unclear.

By using specially crafted requests to change valid SQL queries and perform unexpected actions on vulnerable devices, attackers can take advantage of SQL injection flaws.

“Just as it may be possible to read sensitive information, it is also possible to make changes or even delete this information with a SQL injection attack,” according to MITRE.

According to a JSON file that QNAP released outlining the severity of the vulnerability, it can be easily exploited by remote attackers using low-complexity attacks without the involvement of users or privileges to the targeted device.

Notably, CVE-2022-27596 has not been flagged as being actively exploited in the wild by QNAP’s advisory.

Updates for QNAP NAS Critical Vulnerability

According to QNAP, users should update their devices operating on QTS and QuTS hero to the following versions to stay secure:

  • QTS 5.0.1.2234 build 20221201 and later
  • QuTS hero h5.0.1.2248 build 20221215 and later

Users are encouraged to log in as an administrator to QTS or QuTS hero, navigate to Control Panel > System > Firmware Update, and choose “Check for Update” under the “Live Update” section to install the updates.

Users of QNAP can also manually upgrade their devices by downloading the update from QNAP’s Download Center after choosing the appropriate product type and model.

Hence, users are advised to install any available security upgrades as soon as possible owing to the seriousness of the flaw, since threat actors regularly hunt for QNAP vulnerabilities.

Network Security Checklist – Download Free E-Book

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

5 hours ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

6 hours ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

7 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

7 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

7 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

7 hours ago