ZDI-24-1123: (Pwn2Own) QNAP TS-464 Netmgr Endpoint Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of QNAP TS-464 NAS devices. An attacker must first obtain the ability to make modifications to device configuration in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2024-32765.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1123?
The severity of ZDI-24-1123 is high due to the potential for remote code execution.
How do I fix ZDI-24-1123?
To fix ZDI-24-1123, apply the latest firmware updates from QNAP for the TS-464 NAS device.
What types of attacks can ZDI-24-1123 facilitate?
ZDI-24-1123 can facilitate remote code execution attacks on vulnerable QNAP TS-464 NAS devices.
Who is affected by ZDI-24-1123?
The vulnerability ZDI-24-1123 affects users of QNAP TS-464 NAS devices who have not secured their configuration.
What is required for an attacker to exploit ZDI-24-1123?
An attacker must first gain the ability to modify device configuration to successfully exploit ZDI-24-1123.