ZDI-CAN-22497: ZDI-24-827: (Pwn2Own) QNAP TS-464 username Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of QNAP TS-464 NAS devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-32766.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22497?
ZDI-CAN-22497 has been assigned a CVSS rating of 8, indicating it's a high severity vulnerability.
How do I fix ZDI-CAN-22497?
To mitigate ZDI-CAN-22497, ensure that your QNAP TS-464 NAS device is updated to the latest firmware provided by QNAP.
What type of attack does ZDI-CAN-22497 allow?
ZDI-CAN-22497 allows remote attackers to execute arbitrary code on affected installations of QNAP TS-464 NAS devices.
Is authentication required to exploit ZDI-CAN-22497?
Yes, authentication is required to exploit ZDI-CAN-22497, but the existing mechanism can be bypassed.
What devices are affected by ZDI-CAN-22497?
ZDI-CAN-22497 specifically affects QNAP TS-464 NAS devices.