CVE-2022-23765: IPTIME NAS family CSRF vulnerability
This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the root through a POST request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23765?
CVE-2022-23765 is a vulnerability that allows remote attackers to steal root privileges by changing the password of the root through a malicious POST request on a specific page while logged in as a random user from the IPTIME NAS family.
Which software versions are affected by CVE-2022-23765?
Iptime Nas1dual Firmware version up to 1.4.86 and Iptime Nas2dual Firmware version up to 1.4.86 are affected by CVE-2022-23765.
How severe is CVE-2022-23765?
CVE-2022-23765 has a severity score of 8.8 (high severity).
How can I fix CVE-2022-23765?
To mitigate CVE-2022-23765, it is recommended to update the firmware of the affected IPTIME NAS devices to a version beyond 1.4.86.
Where can I find more information about CVE-2022-23765?
You can find more information about CVE-2022-23765 at the following link: [https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66877](https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66877)