SAM’s security research team revealed two recent vulnerabilities and their potential impacts that are discovered in a specific kind of NAS device (network-attached storage that is used by both organizations and consumers) made by QNAP.
These vulnerabilities are severe as they allow for full takeover of the device from the network including access to the user’s stored data, without any prior knowledge.
The research team discovered two critical vulnerabilities in QNAP TS-231’s latest firmware (version 4.3.6.1446 – 2020/09/29).
The researchers say that these may affect other models and firmware versions as well.
This vulnerability resides in the NAS web server (default TCP port 8080). Previous RCE attacks on QNAP NAS models relied on web pages that do not require prior authentication and run/trigger code on the server-side.
During the inspection, experts fuzzed the webserver with customized HTTP requests to different cgi pages, with a focus on those that do not require prior authentication. This triggers remote code execution indirectly (i.e., triggers some behavior in other processes).
“The vendor can fix the vulnerability by adding input sanitizations to some core processes and library APIs, but it has not been fixed”, suggested by researchers.
This vulnerability resides in the DLNA server (default TCP port 8200). The DLNA server is implemented as the process myupnpmediasvr, and handles UPNP requests on port 8200.
The research discovered this vulnerability during the investigation of the process’s behaviour and communication both externally and internally. It is capable to elevate that vulnerability to remote code execution on the remote NAS as well.
To exploit the bug, researchers created a proof-of-concept attack. “[We used] a python script that we wrote to hack into the device. We achieve a full takeover of the device by using a simple reverse shell technique. After that, we access a file that’s stored on the QNAP storage. Any file stored can be accessed similarly.”, according to researchers at SAM Seamless Network.
Both the vulnerabilities have been reported to QNAP with a 4-month grace period to fix them. Unfortunately, as of now, the vulnerabilities have not yet been fixed.
You can follow us on Linkedin, Twitter, Facebook for daily Cyber security and hacking news updates.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…