ZDI-21-591: QNAP NAS MusicStation Directory Traversal Arbitrary File Creation Vulnerability
This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of QNAP NAS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MusicStation application. When parsing the arttype request parameter, the process does not properly validate a user-supplied path prior to using it in file operations.An attacker can leverage this vulnerability to create files in the context of the admin user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-21-591?
The severity of ZDI-21-591 is considered critical as it allows unauthenticated attackers to create arbitrary files on QNAP NAS devices.
How do I fix ZDI-21-591?
To fix ZDI-21-591, update the MusicStation application on your QNAP NAS to the latest version provided by QNAP.
Which products are affected by ZDI-21-591?
ZDI-21-591 affects QNAP NAS devices that have the MusicStation application installed.
Can ZDI-21-591 be exploited remotely?
Yes, ZDI-21-591 can be exploited remotely as it allows network-adjacent attackers to access the vulnerability.
Is authentication required to exploit ZDI-21-591?
No, authentication is not required to exploit ZDI-21-591, making it more dangerous.