logo

Alert: New Vulnerabilities Discovered in QNAP and Kyocera Device Manager

ID: 0a9bb1a4-ab31-5ac3-a388-340c768ad19f

STIX ID: report--0a9bb1a4-ab31-5ac3-a388-340c768ad19f

Feed Name: The Hacker News

Threat Score
55/100

Date Published: 2024-01-09

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

The report summarizes disclosed vulnerabilities in Kyocera Device Manager (CVE-2023-50916) — an authentication coercion/path traversal issue that can force authentication to attacker-controlled SMB/UNC paths enabling credential capture or NTLM relay — and multiple QNAP product flaws including prototype pollution, XSS, command injection, SQL injection, and an unauthenticated RCE; vendors have released patches and users are advised to update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.