HomeSecurityQNAP VioStor NVR: Vulnerability actively exploited by botnet

QNAP VioStor NVR: Vulnerability actively exploited by botnet

A botnet named 'InfectedSlurs', based on Mirai, exploits a vulnerability in QNAP VioStor NVR (Network Video Recorder) devices to gain control and join its DDoS.

See also: RapperBot botnet: New version with cryptomining capabilities

QNAP VioStor NVR

The botnet was discovered by Akamai's Security Intrusion Response Team (SIRT) in October 2023, which observed the exploitation of two zero-day in routers and NVR devices, likely starting in 2022.

At the time, and because vendors had not released updates, Akamai chose not to disclose any information about the vulnerabilities exploited by InfectedSlurs.

As security updates or information for the two zero-days have become available, Akamai has published two follow-up reports to close the gaps left by the initial report in November.

The first bug exploited by InfectedSlurs is tracked as CVE-2023-49897 and affects the FXC AE1021 and AE1021PE.

The vendor released a security update on December 6, 2023, with firmware version 2.0.10, and recommends that users perform a factory reset and change the default password after applying it.

The second zero-day vulnerability in botnet attacks is CVE-2023-47565, a high-severity operating system command input vulnerability that affects QNAP VioStor NVR models running QVR 4.x.

See also: KV-botnet: Compromises SOHO routers and VPN devices

On December 7, 2023, QNAP published a guide, explaining that the previously unknown issue was fixed in QVR firmware 5.x and later versions, which are available for all actively supported models.

Since version 5.0.0 was released almost a decade ago, it is believed that the Infected Slurs botnet has been attacking older VioStor NVR models that never updated firmware after the initial installation.

botnet

The vendor recommends the following actions for vulnerable NVR devices:

Log in to QVR as an administrator, go to 'Control Panel → System Settings → Software Upgrade,' select the 'Software Upgrade' tab, and click the 'Search' button to locate the correct version for your specific model.

Finally, click on “System Update” and wait for the update to be installed by QVR.

Additionally, it is recommended to change user passwords in QVR via 'Control Panel **'->'Privileges **'->'Users **'->'Change Password', entering a new strong password and clicking 'Apply'.

A VioStor NVR model that has reached end of life (EOL) may not have an update available that includes firmware 5.x or later. These devices will not receive a security update, so the only solution is to replace them with newer, actively supported models.

See also: IPStorm: Botnet with 23,000 servers taken down

One of the most effective security measures to protect against the InfectedSlurs botnet is to update and install the latest software updates on all your devices. Updates often contain security fixes that can prevent the botnet from invading your system.

Another important security measure is to install a reliable antivirus and regularly run scans to detect and remove malware that may be associated with InfectedSlurs.

Additionally, it is important to be cautious with the emails you receive and analyze them carefully before opening any attachments or clicking on links. Malicious senders may use emails to infiltrate your system and install InfectedSlurs.

Finally, user education and awareness are crucial. Inform users about the dangers of the InfectedSlurs botnet and provide instructions on how to browse the web safely and recognize malicious activity.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS