ZDI-26-242: (Pwn2Own) QNAP TS-453E server_handlers.pyc rr2s.kwargs Error Message Information Disclosure Vulnerability
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of QNAP TS-453E devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 3.5. The following CVEs are assigned: CVE-2025-62840.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-242?
ZDI-26-242 is considered a medium severity vulnerability due to its potential to disclose sensitive information.
Who is affected by ZDI-26-242?
ZDI-26-242 affects installations of QNAP TS-453E devices that are network-adjacent.
What type of vulnerability is ZDI-26-242?
ZDI-26-242 is an information disclosure vulnerability that allows attackers to access sensitive information.
How do I fix ZDI-26-242?
To mitigate ZDI-26-242, ensure that your QNAP TS-453E device is updated to the latest firmware provided by QNAP.
Is authentication required to exploit ZDI-26-242?
Yes, authentication is required to exploit the ZDI-26-242 vulnerability.