ZDI-24-826: (Pwn2Own) QNAP TS-464 Improper Validation Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of QNAP TS-464 NAS devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-32766.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-826?
The severity of ZDI-24-826 is rated at 9.8 on the CVSS scale, indicating a critical vulnerability.
How do I fix ZDI-24-826?
To fix ZDI-24-826, update your QNAP TS-464 NAS device to the latest firmware version provided by QNAP.
What impact does ZDI-24-826 have on user security?
ZDI-24-826 allows remote attackers to bypass authentication, posing a significant risk to user data and system security.
Is there a workaround for ZDI-24-826?
Currently, there are no known workarounds for ZDI-24-826; immediate firmware updates are recommended.
What systems are affected by ZDI-24-826?
ZDI-24-826 specifically affects QNAP TS-464 NAS devices.