logo

Zero-Day in QNAP QTS Affects NAS Devices Globally

ID: 68ed0f4f-7bcf-5145-878b-d70fb83e0b4e

STIX ID: report--68ed0f4f-7bcf-5145-878b-d70fb83e0b4e

Feed Name: HackRead

Threat Score
80/100

Date Published: 2024-02-14

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Unit 42 disclosed a critical unauthenticated command-injection zero-day (CVE-2023-50358) in QNAP QTS/QuTS hero quick.cgi that enables remote command execution via the SPECIFIC_SERVER parameter; QNAP published an advisory and released firmware updates (e.g., QTS 5.1.5 / QuTS hero h5.1.5) as mitigations. The issue impacts hundreds of thousands of exposed IPs globally and should be addressed immediately by applying vendor patches or recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.