logo

QNAP fixes NAS backup software zero-day exploited at Pwn2Own

ID: ed94a40d-842d-5e71-83f0-c0530e3da089

STIX ID: report--ed94a40d-842d-5e71-83f0-c0530e3da089

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-10-29

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

QNAP released a patch for CVE-2024-50388, a critical OS command injection zero-day in HBS 3 Hybrid Backup Sync 25.1.x that was demonstrated by Viettel Cyber Security at Pwn2Own Ireland 2024 to gain arbitrary command execution and admin privileges; the vendor fixed the issue in version 25.1.1.673 and the advisory reminds users to update, noting historical ransomware activity against QNAP NAS devices that increases risk if the vulnerability were abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.