Advisory Details

May 19th, 2024

(Pwn2Own) QNAP TS-464 QR Code Device CRLF Injection Arbitrary Configuration Change Vulnerability

ZDI-24-470
ZDI-CAN-22493

CVE ID CVE-2024-21899
CVSS SCORE 9.1, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
AFFECTED VENDORS QNAP
AFFECTED PRODUCTS TS-464
VULNERABILITY DETAILS

This vulnerability allows remote attackers to make arbitrary changes to configuration on affected installations of QNAP TS-464 NAS devices. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the privWizard API endpoints. The issue results from the lack of proper validation of a user-supplied string before using it to update configuration. An attacker can leverage this vulnerability to change the configuration of the system.

ADDITIONAL DETAILS QNAP has issued an update to correct this vulnerability. More details can be found at:
https://www.qnap.com/en/security-advisory/qsa-24-09
DISCLOSURE TIMELINE
  • 2023-11-09 - Vulnerability reported to vendor
  • 2024-05-19 - Coordinated public release of advisory
  • 2024-07-01 - Advisory Updated
CREDIT LJP (@ljp_tw) and YingMuo (@YingMuo), working with DEVCORE Internship Program
BACK TO ADVISORIES