logo

QNAP vulnerability disclosure ends up an utter shambles

ID: b63852da-37c8-5d05-8f72-3b4d30abd3a4

STIX ID: report--b63852da-37c8-5d05-8f72-3b4d30abd3a4

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-02-13

Date Updated: 2026-04-26

Author: Connor Jones

...
...

QNAP disclosed and released fixes for two command-injection vulnerabilities in its QTS/QuTS firmware (CVE-2023-50358 and CVE-2023-47218), with Unit42 publishing a technical breakdown showing how unauthenticated input to quick.cgi can lead to arbitrary command execution; the advisory and vendor patches cover many firmware branches while the German BSI warned of potential "major damage." Unit42's internet scans found about 289,665 exposed devices worldwide, there is disagreement between QNAP's moderate CVSS assignment and researchers' higher-impact assessment, and users are urged to apply the provided patches or mitigations promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.