logo

QNAP QTS zero-day in Share feature gets public RCE exploit

ID: 4dc5d612-874d-589c-9617-874ab50bc65a

STIX ID: report--4dc5d612-874d-589c-9617-874ab50bc65a

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-05-20

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

An audit by WatchTowr Labs found fifteen vulnerabilities in QNAP QTS (eleven initially unpatched), including CVE-2024-27130—a stack-buffer overflow in share.cgi allowing remote code execution when an attacker can obtain a shared-link SSID; a proof-of-concept exploit was published and QNAP later released emergency patches for several issues while others remained unaddressed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.