CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-32766

CVSS 10.0v3.1pub. 2024-04-26upd. 2025-12-10

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

🤖 AI Analysis
How it works

The vulnerability (CWE-77, CWE-78) consists of insufficient validation or neutralization of input data passed to the operating system command interpreter. An attacker can send a specially crafted request over the network containing malicious commands that will be executed in the context of the NAS device's operating system. The network attack vector (AV:N), lack of required privileges (PR:N), and absence of user interaction (UI:N) make the attack fully remote and automated.

Impact

Successful exploitation of the vulnerability allows an attacker to execute arbitrary system commands on the QNAP NAS device, which can lead to complete device takeover, data breach, modification or destruction of data, as well as the use of the device as an entry point to the internal network (lateral movement).

Mitigation & patch

Software must be immediately updated to the following versions: QTS 5.1.3.2578 build 20231110 or newer, QTS 4.5.4.2627 build 20231225 or newer, QuTS hero h5.1.3.2578 build 20231110 or newer, QuTS hero h4.5.4.2626 build 20231225 or newer, QuTScloud c5.1.5.2651 or newer. Additionally, it is recommended to restrict access to the device management panel exclusively to trusted IP addresses and disable direct internet access if not required.

Who is affected

QNAP QTS in versions prior to 5.1.3.2578 build 20231110 and prior to 4.5.4.2627 build 20231225; QuTS hero in versions prior to h5.1.3.2578 build 20231110 and prior to h4.5.4.2626 build 20231225; QuTScloud in versions prior to c5.1.5.2651

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Qnap Qts

    OS
    Qnap
    4.5.4.26275.1.3.2578< 4.5.4.26275.0.0 – 5.1.3.2578 (excl.)
  • Qnap Qutscloud

    OS
    Qnap
    c5.0.0.1919 – c5.1.5.2651 (excl.)
  • Qnap Quts Hero

    OS
    Qnap
    h4.5.4.2626h5.1.3.2578h5.0.0 – h5.1.3.2578 (excl.)h4.5.0 – h4.5.4.2626 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2022-27593CRITICAL10.0⚠ KEVPL ✓same product

QNAP Photo Station — niekontrolowane odniesienie do zewnętrznego zasobu (RCE/modyfikacja plików)

CVE-2021-28799CRITICAL10.0⚠ KEVPL ✓same product

QNAP HBS 3 — nieautoryzowane logowanie zdalne do urządzenia NAS

CVE-2020-2509CRITICAL9.8⚠ KEVPL ✓same product

Command injection w QNAP QTS i QuTS hero — zdalne wykonanie kodu

CVE-2018-19949CRITICAL9.8⚠ KEVPL ✓same product

Command injection w QNAP QTS umożliwiający zdalne wykonanie kodu

CVE-2019-7194CRITICAL9.8⚠ KEVPL ✓same product

Path Traversal w QNAP Photo Station umożliwia zdalny dostęp do plików