ZDI-CAN-22494: ZDI-24-471: (Pwn2Own) QNAP TS-464 authLogin SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of QNAP TS-464 NAS devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-21901.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22494?
The severity of ZDI-CAN-22494 is rated at 8 on the CVSS scale, indicating a high-risk vulnerability.
How do I fix ZDI-CAN-22494?
To fix ZDI-CAN-22494, ensure that your QNAP TS-464 firmware is updated to the latest version provided by QNAP.
What systems are affected by ZDI-CAN-22494?
ZDI-CAN-22494 affects QNAP TS-464 NAS devices specifically.
Can ZDI-CAN-22494 be exploited without authentication?
Although authentication is generally required, the existing authentication mechanism for ZDI-CAN-22494 can be bypassed.
What type of vulnerability is ZDI-CAN-22494?
ZDI-CAN-22494 is a remote code execution vulnerability that allows attackers to execute arbitrary code on affected devices.