QNAP released a critical security update on June 17 to address fourteen vulnerabilities in its network storage operating systems. These flaws range from credential theft risks to arbitrary command execution, posing direct threats to users who store sensitive data on their devices. Administrators must apply these patches immediately to prevent unauthorized access to their network-attached storage units.
Critical flaws include credential theft and command injection risks
The advisory targets the QTS, QuTS hero, QuTS cloud, and QVP operating systems. Specific affected versions include QTS 5.2.7, QuTS hero h5.2.8, QuTS cloud c5.2.8, and QVP 2.7.1. Users running these older builds are exposed to various exploitation methods that could compromise system integrity.
Critical flaws include URL injection vulnerabilities that allow attackers to steal credentials through fake password reset links. Command injection issues enable authenticated administrators to execute arbitrary system commands on the device. A memory vulnerability in the file upload process can be exploited by unauthenticated attackers using manipulated uploads with long filenames.
QNAP has resolved these issues in the latest software releases. The company advises users to update their systems to QTS 5.2.9.3499 or QuTS hero h5.2.9. These fixed versions close the security gaps identified in the advisory and restore full protection for NAS environments.
This update resolves the security gaps identified in advisory QSA-26-10. Users who apply the recommended fixes eliminate the risk of credential theft and unauthorized command execution. Maintaining current operating system versions remains the primary defense against these known vulnerabilities.
Source: NotebookCheck




Discussion
0 comments