ZDI-26-244: (Pwn2Own) QNAP QHora-322 miro_webserver_controllers_api_login_singIn Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of QNAP QHora-322 routers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2024-13088.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-244?
The severity of ZDI-26-244 is considered critical due to its potential for unauthorized access.
How do I fix ZDI-26-244?
To fix ZDI-26-244, apply the latest firmware update provided by QNAP for the QHora-322 router.
What type of vulnerability is ZDI-26-244?
ZDI-26-244 is an authentication bypass vulnerability that allows attackers to gain access without proper credentials.
Who is affected by ZDI-26-244?
Any user of the QNAP QHora-322 router is potentially affected by ZDI-26-244.
Can ZDI-26-244 be exploited remotely?
Yes, ZDI-26-244 can be exploited by network-adjacent attackers without any authentication.