ZDI-24-472: (Pwn2Own) QNAP TS-464 Netmgr Endpoint CRLF Injection Arbitrary Configuration Update Vulnerability
This vulnerability allows remote attackers to create arbitrary configurations on affected installations of QNAP TS-464 NAS devices. An attacker must first obtain the ability to access the device's localhost interface, which can be accomplished using a malicious TURN server. The ZDI has assigned a CVSS rating of 7.4. The following CVEs are assigned: CVE-2024-32764.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-472?
The severity of ZDI-24-472 is considered high due to its potential for remote exploitation.
How do I fix ZDI-24-472?
To fix ZDI-24-472, ensure your QNAP TS-464 device is updated to the latest firmware provided by QNAP.
Can ZDI-24-472 be exploited without local access?
Yes, ZDI-24-472 can be exploited if an attacker gains access to the device's localhost interface via a malicious TURN server.
What devices are affected by ZDI-24-472?
ZDI-24-472 specifically affects QNAP TS-464 NAS devices.
What are the implications of ZDI-24-472 for users?
Users may face unauthorized configuration changes and potential loss of data if ZDI-24-472 is exploited.