QNAP has patched six rsync vulnerabilities that could allow remote code execution on unpatched NAS devices.
See also: QNAP fixes vulnerabilities found in Pwn2Own

Rsync is a powerful open source file synchronization and transfer tool known for its speed and efficiency. It supports direct synchronization via its own daemon, secure transfers via SSH, and incremental transfers that reduce the time required and bandwidth consumption . It is particularly popular in backup solutions such as Rclone , DeltaCopy , and ChronoSync , and is widely used in cloud management , servers, and public file distribution.
The vulnerabilities are tracked as CVE-2024-12084 (heap buffer overflow), CVE-2024-12085 (information leakage via uninitialized stack), CVE-2024-12086 (server leakage of arbitrary client files), CVE-2024-12087 (path traversal via –inc-recursive option), CVE-2024-12088 (bypass of –safe-links option), and CVE-2024-12747.
QNAP says they affect HBS 3 Hybrid Backup Sync 25.1.x , the company's data backup and recovery solution , which supports local, remote, and cloud storage services.
See also: QNAP fixed critical vulnerabilities in various products
In a security advisory released on Thursday, QNAP said it addressed these vulnerabilities in HBS 3 Hybrid Backup Sync 25.1.4.952 and advised customers to update their software to the latest version.

To update the Hybrid Backup Sync installation on your NAS device, you will need to:
- Log in to QTS or QuTS hero as an administrator
- Open the App Center and search for HBS 3 Hybrid Backup Sync
- Wait for HBS 3 Hybrid Backup Sync to appear in the search results
- Click Update and then OK on the next confirmation message.
These Rsync flaws can be combined to create exploit chains that lead to remote compromise . Attackers only require anonymous read access to vulnerable servers.
A Shodan search reveals more than 700,000 IP addresses with exposed rsync servers. However, it is unclear how many of these are vulnerable to attacks that exploit these vulnerabilities, as successful exploitation requires valid credentials or servers configured for anonymous connections.
See also: QNAP fixes second zero-day vulnerability presented at Pwn2Own Ireland
Remote Code Execution (RCE) is a serious security vulnerability in software systems. Through this vulnerability, a malicious user can execute arbitrary code on a remote device or server without authorization. This can lead to serious consequences, such as data breach, complete system control, or malware distribution. Developers and system administrators are urged to implement robust security practices, such as software updates, proper input handling, and firewall usage, to reduce the risk of RCE.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
