ZDI-CAN-28324: ZDI-26-198: (Pwn2Own) QNAP TS-453E malware_remover Code Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of QNAP TS-453E devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-11837.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28324?
ZDI-CAN-28324 is classified as a critical vulnerability due to its potential for remote code execution without authentication.
How do I fix ZDI-CAN-28324?
To fix ZDI-CAN-28324, ensure your QNAP TS-453E device is updated to the latest firmware version provided by QNAP.
Who is affected by ZDI-CAN-28324?
The vulnerability affects all installations of the QNAP TS-453E device without proper security updates.
What type of vulnerability is ZDI-CAN-28324?
ZDI-CAN-28324 is a code injection vulnerability that allows for remote code execution by network-adjacent attackers.
Is authentication required to exploit ZDI-CAN-28324?
No, authentication is not required to exploit ZDI-CAN-28324, making it particularly dangerous.