Command Injection Vulnerability in QNAP Operating Systems
CVE-2024-53692

5.1MEDIUM

Key Information:

Vendor
QNAP
Vendor
CVE Published:
7 March 2025

Summary

A command injection vulnerability has been identified in various versions of the QNAP operating systems. This flaw may allow remote attackers, who have gained administrator access, to execute arbitrary commands on the affected systems. If left unpatched, this could potentially lead to unauthorized control and compromise of sensitive data. QNAP has addressed this issue in specific updates, and users are urged to upgrade to QTS 5.2.3.3006 build 20250108 or later, and QuTS hero h5.2.3.3006 build 20250108 or later to mitigate this risk.

Affected Version(s)

QTS 5.2.x < 5.2.3.3006 build 20250108

QuTS hero h5.2.x

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZIEN
.