ZDI-24-471: (Pwn2Own) QNAP TS-464 authLogin SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of QNAP TS-464 NAS devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-21901.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-471?
The ZDI-24-471 vulnerability has been assigned a CVSS rating of 8, indicating a high severity risk.
How do I fix ZDI-24-471?
To mitigate ZDI-24-471, you should update the firmware of your QNAP TS-464 NAS device to the latest version provided by QNAP.
What kind of attack does ZDI-24-471 facilitate?
ZDI-24-471 allows remote attackers to execute arbitrary code on affected QNAP TS-464 NAS devices.
Is authentication required to exploit ZDI-24-471?
Yes, although authentication is required to exploit ZDI-24-471, the existing authentication mechanism can be bypassed.
Which devices are affected by ZDI-24-471?
The ZDI-24-471 vulnerability specifically affects QNAP TS-464 NAS devices.