Experts released PoC exploit code for RCE in QNAP QTS
ID: 58c4cdaa-c91b-5cb9-b4a4-c75db0120c0f
STIX ID: report--58c4cdaa-c91b-5cb9-b4a4-c75db0120c0f
Feed Name: Security Affairs
Threat Score
Researchers from WatchTowr Labs disclosed fifteen vulnerabilities affecting QNAP QTS, QuTScloud, and QTS hero, highlighting CVE-2024-27130 — an unsafe strcpy in share.cgi leading to a stack buffer overflow and potential remote code execution. Technical details and proof-of-concept exploit code were published; only four of the fifteen flaws were patched by QNAP in April 2024, while the remainder remain unpatched, under embargo, or accepted by the vendor without fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
