ZDI-24-827: (Pwn2Own) QNAP TS-464 username Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of QNAP TS-464 NAS devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-32766.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-827?
ZDI-24-827 has a CVSS rating of 8, indicating a high severity level.
How do I fix ZDI-24-827?
To fix ZDI-24-827, ensure that your QNAP TS-464 NAS device has the latest security updates installed.
Who can exploit ZDI-24-827?
While ZDI-24-827 requires authentication to exploit, the authentication mechanism can be bypassed by attackers.
What type of vulnerability is ZDI-24-827?
ZDI-24-827 is a remote code execution vulnerability affecting QNAP TS-464 NAS devices.
What devices are affected by ZDI-24-827?
ZDI-24-827 specifically affects QNAP TS-464 NAS devices.