ZDI-CAN-22410: ZDI-24-475: (Pwn2Own) QNAP TS-464 File Upload Directory Traversal Arbitrary File Creation Vulnerability
This vulnerability allows remote attackers to create arbitrary files on affected installations of QNAP TS-464 NAS devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2023-51364.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22410?
The vulnerability ZDI-CAN-22410 has a CVSS rating of 6.5, indicating a medium severity.
How do I fix ZDI-CAN-22410?
To remediate ZDI-CAN-22410, ensure you update your QNAP TS-464 NAS device to the latest firmware that addresses this vulnerability.
What types of attacks can ZDI-CAN-22410 facilitate?
ZDI-CAN-22410 allows remote attackers to create arbitrary files on affected QNAP TS-464 NAS devices without authentication.
Which devices are affected by ZDI-CAN-22410?
ZDI-CAN-22410 specifically affects QNAP TS-464 NAS devices.
Is authentication required to exploit ZDI-CAN-22410?
No, authentication is not required to exploit the vulnerability ZDI-CAN-22410.