logo

QNAP patches second zero-day exploited at Pwn2Own to get root

ID: 4b7f612e-b892-552e-9ad9-668597c3eb36

STIX ID: report--4b7f612e-b892-552e-9ad9-668597c3eb36

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-10-30

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

QNAP issued emergency patches for two zero-day vulnerabilities disclosed at Pwn2Own Ireland 2024 — notably CVE-2024-50387, an SQL injection in the SMB Service that enabled root access on a TS-464 NAS — and advises administrators to update affected QuTS/QTS components. The advisory highlights the high-risk profile of internet-exposed QNAP devices, citing past ransomware families (eCh0raix, DeadBolt, Checkmate) that have leveraged NAS vulnerabilities and weak credentials, and recommends prompt patching to mitigate potential compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.