GAMES GTA 6 Satirizes Streamers With Trunk Challenge Scene INTEL Akasa Newton N16 Fanless Case Launches for ASUS NUC 16 Pro GAMES INTERSCAPE Game Preview: Inception Meets Control at Tokyo Game Show GAMES Marvel’s Wolverine Update 1.001.005 Reduces Scent Trails Intensity GAMES The Last of Us Co-Director Apologizes for Criticizing AAA Game Innovation GAMES 86% of Japanese Game Developers Now Use Generative AI GAMES THE FINALS Update Evolves Game Show Mode Ahead of October 20 Launch GAMES ARC Raiders Frozen Trail Update Lands October 8 as Largest Expansion AMD Sony Project Canis handheld may beat base PS5 with 540p rendering NVIDIA RTX 3060 with RTX 4090 Cooler Drops Temps 9C, Gains 2FPS GAMES Call of Duty Team RICOCHET Dismantles Cheating Industry Infrastructure AMD STALKER 2 Patch 2.0.6 Fixes AMD GPU Crashes and Stability Issues GAMES Bruce Straley Apologizes for Using God of War Laufey in AAA Critique GAMES NBA 2K Virtual Currency Will Not Carry Over to Next Annual Release

QNAP Fixes 14 Critical NAS Security Flaws in Latest Update

Daniel Cross 2 min read

QNAP released a critical security update addressing 14 vulnerabilities in its NAS operating systems, including QTS and QuTS, urging immediate updates.

QNAP QNAP NAS
SOFTWARE AND UPDATES

QNAP released a critical security update on June 17 to address fourteen vulnerabilities in its network storage operating systems. These flaws range from credential theft risks to arbitrary command execution, posing direct threats to users who store sensitive data on their devices. Administrators must apply these patches immediately to prevent unauthorized access to their network-attached storage units.

Critical flaws include credential theft and command injection risks

The advisory targets the QTS, QuTS hero, QuTS cloud, and QVP operating systems. Specific affected versions include QTS 5.2.7, QuTS hero h5.2.8, QuTS cloud c5.2.8, and QVP 2.7.1. Users running these older builds are exposed to various exploitation methods that could compromise system integrity.

Critical flaws include URL injection vulnerabilities that allow attackers to steal credentials through fake password reset links. Command injection issues enable authenticated administrators to execute arbitrary system commands on the device. A memory vulnerability in the file upload process can be exploited by unauthenticated attackers using manipulated uploads with long filenames.

QNAP has resolved these issues in the latest software releases. The company advises users to update their systems to QTS 5.2.9.3499 or QuTS hero h5.2.9. These fixed versions close the security gaps identified in the advisory and restore full protection for NAS environments.

This update resolves the security gaps identified in advisory QSA-26-10. Users who apply the recommended fixes eliminate the risk of credential theft and unauthorized command execution. Maintaining current operating system versions remains the primary defense against these known vulnerabilities.

Source: NotebookCheck