QNAP patches second zero-day exploited at Pwn2Own to get root
ID: 4b7f612e-b892-552e-9ad9-668597c3eb36
STIX ID: report--4b7f612e-b892-552e-9ad9-668597c3eb36
Feed Name: Bleeping Computer
QNAP issued emergency patches for two zero-day vulnerabilities disclosed at Pwn2Own Ireland 2024 — notably CVE-2024-50387, an SQL injection in the SMB Service that enabled root access on a TS-464 NAS — and advises administrators to update affected QuTS/QTS components. The advisory highlights the high-risk profile of internet-exposed QNAP devices, citing past ransomware families (eCh0raix, DeadBolt, Checkmate) that have leveraged NAS vulnerabilities and weak credentials, and recommends prompt patching to mitigate potential compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
