ZDI-26-216: (Pwn2Own) QNAP TS-453E smbd domain_name Argument Injection Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of QNAP TS-453E devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2025-62847.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-216?
ZDI-26-216 is considered critical due to its authentication bypass nature that allows unauthorized access.
How do I fix ZDI-26-216?
To fix ZDI-26-216, update the QNAP TS-453E device to the latest firmware version provided by the vendor.
Who is affected by ZDI-26-216?
Any user of the QNAP TS-453E device is impacted by ZDI-26-216 as it allows an authentication bypass.
Can ZDI-26-216 be exploited remotely?
Yes, ZDI-26-216 can be exploited by network-adjacent attackers without the need for authentication.
What devices are vulnerable to ZDI-26-216?
The QNAP TS-453E device is specifically vulnerable to ZDI-26-216, making it a target for exploitation.