Taiwanese hardware vendor QNAP on Monday urged customers to disable Universal Plug and Play (UPnP) port forwarding on their routers to prevent network-attached storage (NAS) devices from being exposed to attacks from the Internet.

Is UPnP Port Forwarding secure?
UPnP is not a secure protocol. It uses network UDP multicasts, without encryption and without authentication. Since UPnP is not authenticated, one device could request a port mapping for another. Hackers can abuse UPnP to attack via malicious files to infect your system and gain control. Despite its convenience, UPnP can expose your device to public networks and malicious attacks.
UPnP Port Forwarding allows network devices to communicate seamlessly and create groups for easier data sharing.
"It is recommended that your QNAP NAS remain behind a router and firewall without a public IP address. You should disable manual port forwarding and UPnP auto port forwarding for the QNAP NAS in your router configuration," QNAP said today.
As options for those who need access to NAS devices without direct Internet, QNAP recommends enabling the router's VPN feature (if available), the myQNAPcloud Link service, and the VPN server on QNAP devices provided by the QVPN Service app or the QuWAN SD-WAN solution.

NAS devices exposed to the Internet at risk
QNAP warned customers back in January to immediately protect their NAS devices from active ransomware and brute-force attacks.
The company asked users to check if their NAS is accessible over the Internet and take the following steps to defend them from incoming hacking attempts:
- Disable the router's Port Forwarding feature: Go to your router's management interface, check the Virtual Server, NAT, or Port Forwarding settings, and disable the port forwarding setting of the NAS management service port (ports 8080 and 433 by default).
- Disable the UPnP function of the QNAP NAS: Go to myQNAPcloud in the QTS menu, click “Auto Router Configuration” and uncheck “Enable UPnP Port forwarding”.
QNAP also provides step-by-step instructions for disabling SSH and Telnet connections, changing the system port number and device password , and enabling IP and account access protection .
Information source: bleepingcomputer.com
