ZDI-CAN-22458: ZDI-24-1123: (Pwn2Own) QNAP TS-464 Netmgr Endpoint Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of QNAP TS-464 NAS devices. An attacker must first obtain the ability to make modifications to device configuration in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2024-32765.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22458?
ZDI-CAN-22458 has been assigned a high severity rating due to the potential for remote code execution.
How do I fix ZDI-CAN-22458?
To fix ZDI-CAN-22458, ensure your QNAP TS-464 NAS devices are updated to the latest firmware.
What types of attacks can exploit ZDI-CAN-22458?
ZDI-CAN-22458 can be exploited by remote attackers to execute arbitrary code on the affected NAS devices.
What are the prerequisites for exploiting ZDI-CAN-22458?
An attacker must first obtain the ability to modify the device configuration to exploit ZDI-CAN-22458.
What are the potential impacts of ZDI-CAN-22458?
Exploiting ZDI-CAN-22458 could lead to unauthorized remote access and control over sensitive data on the QNAP TS-464.