If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HQnap Qts
OSQnap4.2.64.3.1.0013 – 4.3.3.1161 (excl.)4.3.4 – 4.3.4.1190 (excl.)< 4.2.64.4.0 – 4.4.1.1201 (excl.)4.4.2 – 4.4.2.1231 (excl.)4.3.6 – 4.3.6.1218 (excl.)
CISA KEV — detailsi
- Vendori
- QNAP
- Producti
- Network Attached Storage (NAS)
- Added to KEVi
- May 24, 2022
- Remediation deadline (US Federal)i
- June 14, 2022(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply updates per vendor instructions.
A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
Related vulnerabilities
QNAP Photo Station — niekontrolowane odniesienie do zewnętrznego zasobu (RCE/modyfikacja plików)
QNAP HBS 3 — nieautoryzowane logowanie zdalne do urządzenia NAS
Command injection w QNAP QTS i QuTS hero — zdalne wykonanie kodu
QNAP Photo Station — path traversal umożliwiający dostęp do plików systemowych
QNAP Photo Station — nieautoryzowany dostęp zdalny (RCE)