Zero-Day in QNAP QTS Affects NAS Devices Globally
ID: 68ed0f4f-7bcf-5145-878b-d70fb83e0b4e
STIX ID: report--68ed0f4f-7bcf-5145-878b-d70fb83e0b4e
Feed Name: HackRead
Threat Score
Unit 42 disclosed a critical unauthenticated command-injection zero-day (CVE-2023-50358) in QNAP QTS/QuTS hero quick.cgi that enables remote command execution via the SPECIFIC_SERVER parameter; QNAP published an advisory and released firmware updates (e.g., QTS 5.1.5 / QuTS hero h5.1.5) as mitigations. The issue impacts hundreds of thousands of exposed IPs globally and should be addressed immediately by applying vendor patches or recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
