logo

Experts released PoC exploit code for RCE in QNAP QTS

ID: 58c4cdaa-c91b-5cb9-b4a4-c75db0120c0f

STIX ID: report--58c4cdaa-c91b-5cb9-b4a4-c75db0120c0f

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2024-05-21

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Researchers from WatchTowr Labs disclosed fifteen vulnerabilities affecting QNAP QTS, QuTScloud, and QTS hero, highlighting CVE-2024-27130 — an unsafe strcpy in share.cgi leading to a stack buffer overflow and potential remote code execution. Technical details and proof-of-concept exploit code were published; only four of the fifteen flaws were patched by QNAP in April 2024, while the remainder remain unpatched, under embargo, or accepted by the vendor without fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.