ZDI-CAN-22457: ZDI-24-472: (Pwn2Own) QNAP TS-464 Netmgr Endpoint CRLF Injection Arbitrary Configuration Update Vulnerability
This vulnerability allows remote attackers to create arbitrary configurations on affected installations of QNAP TS-464 NAS devices. An attacker must first obtain the ability to access the device's localhost interface, which can be accomplished using a malicious TURN server. The ZDI has assigned a CVSS rating of 7.4. The following CVEs are assigned: CVE-2024-32764.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22457?
The severity of ZDI-CAN-22457 is considered critical due to the potential for remote attackers to manipulate device configurations.
How do I fix ZDI-CAN-22457?
To fix ZDI-CAN-22457, ensure that your QNAP TS-464 device is updated to the latest firmware that addresses this vulnerability.
What impact does ZDI-CAN-22457 have on QNAP TS-464 users?
ZDI-CAN-22457 allows remote attackers to create arbitrary configurations, which can lead to compromised security and unauthorized access.
Who is affected by the ZDI-CAN-22457 vulnerability?
Users of the QNAP TS-464 NAS devices are affected by the ZDI-CAN-22457 vulnerability.
What are the prerequisites for exploiting ZDI-CAN-22457?
An attacker must obtain access to the device's localhost interface to exploit ZDI-CAN-22457, potentially through a malicious TURN server.