HomeSecurityQNAP: Fixes bug that allows remote command execution

QNAP: Fixes bug that allows remote command execution

Taiwan-based network attached storage (NAS) manufacturer QNAP has released security patches for multiple vulnerabilities that could allow attackers to remotely inject and execute malicious code and commands on vulnerable NAS devices.

QNAP

See also: Microsoft Exchange: New feature automatically mitigates high-risk bugs

Three of the security flaws patched by QNAP today are high-severity cross-site scripting (XSS) vulnerabilities (listed as CVE-2021-34354, CVE-2021-34356, and CVE-2021-34355) that affect devices running unpatched Photo Station software (releases prior to 5.4.10, 5.7.13, or 6.0.18).

QNAP is also patching a stored Image2PDF XSS flaw that affects devices running software versions released before Image2PDF 2.1.5.

Stored XSS attacks allow threat actors to inject malicious code remotely, permanently storing it on targeted servers after successful exploitation.

The company also addressed a command injection flaw (CVE-2021-34352) affecting some QNAP end-of-life (EOL) devices running the QVR IP video surveillance software that helps attackers execute arbitrary commands.

Successful attacks exploiting the CVE-2021-34352 flaw could lead to the complete takeover of compromised NAS devices.

Three more flaws were patched on Monday, as disclosed by QNAP in a security advisory rated critical.

See also: Apple: Fixes new zero-day bug that is actively used!

How to secure your NAS device

Since QNAP NAS devices have been under constant attack for the past two years, customers should immediately update both applications to the latest available versions as soon as possible.

To update Photo Station or Image2PDF to the latest version on your NAS, you need to follow the following procedure:

  • Log in to QTS or QuTS as an administrator.
  • Open App Center, then press ENTER. A search box appears.
  • Type “Photo Station” or “Image2PDF,” then press ENTER. The app appears in the search results.
  • Click Update. A confirmation message appears. Note: The Update button is unavailable if you are using the latest version.
  • Click OK. The application is updated.

To update the QVR monitoring software, follow these steps:

  • Log in to QVR as an administrator.
  • Go to Control Panel > System Settings > Firmware Update.
  • In the Live Update section, click Check for Update. QVR downloads and installs the latest available update.

See also: iOS 15 bug: Sound doesn't work on Instagram Stories

QNAP warned in September 2020 of an increase in ransomware that encrypt files on publicly exposed NAS storage devices.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS