CVE-2021-26620: IPTIME NAS2dual improper authentication vulnerability
An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26620?
CVE-2021-26620 is an improper authentication vulnerability in iptime NAS2dual that can lead to information leakage.
How severe is CVE-2021-26620?
CVE-2021-26620 has a severity score of 7.5, which is considered high.
Which software versions are affected by CVE-2021-26620?
The Iptime Nas101 Firmware, Iptime Nas1dual Firmware, Iptime Nas2dual Firmware, Iptime Nas3 Firmware, Iptime Nas4 Firmware, Iptime Nas4dual Firmware, Iptime Nas-i Firmware, Iptime Nas-ii Firmware, and Iptime Nas-iie Firmware versions up to 1.4.82 are affected by CVE-2021-26620.
What can an attacker do with CVE-2021-26620?
An attacker can exploit CVE-2021-26620 to steal important information in the server, such as by accessing the shared folder and changing a user's password.
Is there a fix for CVE-2021-26620?
At the moment, there is no specific fix mentioned for CVE-2021-26620. It is recommended to apply any patches or updates provided by the vendor and follow best practices for secure authentication.