CRLF Injection Vulnerability in QNAP Operating System Versions
CVE-2024-53693

7.1HIGH

Key Information:

Vendor
QNAP
Vendor
CVE Published:
7 March 2025

Summary

A vulnerability has been identified in several versions of the QNAP operating system, specifically related to improper neutralization of CRLF sequences, known as CRLF injection. This flaw could potentially enable remote attackers with user-level access to alter application data, posing a significant risk to system integrity and data confidentiality. Users are urged to upgrade to QTS 5.2.3.3006 (build 20250108) or later, as well as QuTS hero h5.2.3.3006 (build 20250108) or later, to mitigate this risk.

Affected Version(s)

QTS 5.2.x < 5.2.3.3006 build 20250108

QuTS hero h5.2.x

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Searat and izut
.