ZDI-CAN-28327: ZDI-26-292: QNAP TS-453E QVRPro excpostgres Exposed Dangerous Method Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of QNAP TS-453E devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-22898.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28327?
The severity of ZDI-CAN-28327 is critical due to its potential to allow remote code execution without authentication.
How do I fix ZDI-CAN-28327?
To fix ZDI-CAN-28327, update your QNAP TS-453E and QVR Pro (excpostgres) to the latest firmware that addresses this vulnerability.
Who is affected by ZDI-CAN-28327?
Affected users are those running QNAP TS-453E devices and QVR Pro (excpostgres) software that have not applied the necessary updates.
What type of vulnerability is ZDI-CAN-28327?
ZDI-CAN-28327 is a remote code execution vulnerability that can be exploited by network-adjacent attackers.
Is authentication required to exploit ZDI-CAN-28327?
No, authentication is not required to exploit ZDI-CAN-28327, making it more dangerous.