CVE ID | CVE-2024-21899 |
CVSS SCORE | 9.1, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
AFFECTED VENDORS |
QNAP |
AFFECTED PRODUCTS |
TS-464 |
VULNERABILITY DETAILS |
This vulnerability allows remote attackers to make arbitrary changes to configuration on affected installations of QNAP TS-464 NAS devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the privWizard API endpoints. The issue results from the lack of proper validation of a user-supplied string before using it to update configuration. An attacker can leverage this vulnerability to change the configuration of the system. |
ADDITIONAL DETAILS |
QNAP has issued an update to correct this vulnerability. More details can be found at:
https://www.qnap.com/en/security-advisory/qsa-24-09 |
DISCLOSURE TIMELINE |
|
CREDIT | LJP (@ljp_tw) and YingMuo (@YingMuo), working with DEVCORE Internship Program |