logo

QNAP warns of critical auth bypass flaw in its NAS devices

ID: 1cdb0e09-3fe1-5ec1-98a5-0159d7fcd2a3

STIX ID: report--1cdb0e09-3fe1-5ec1-98a5-0159d7fcd2a3

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-03-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

QNAP disclosed three vulnerabilities affecting QTS, QuTS hero, QuTScloud and myQNAPcloud — an unauthenticated remote authentication bypass (CVE-2024-21899) and two authenticated flaws enabling command injection (CVE-2024-21900) and SQL injection (CVE-2024-21901). The advisory lists affected versions, provides patched version numbers and update instructions, and warns that internet-exposed NAS devices are attractive targets for ransomware families such as DeadBolt, Checkmate, and Qlocker.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.