QNAP behebt kritische Schwachstellen in NAS- und Router-Software

Teilen:

QNAP has released security bulletins over the weekend, which address multiple vulnerabilities, including three critical severity flaws that users should address as soon as possible.

Starting with QNAP Notes Station 3, a note-taking and collaboration application used in the firm’s NAS systems, the following two vulnerabilities impact it:

  • CVE-2024-38643 – Missing authentication for critical functions could allow remote attackers to gain unauthorized access and execute specific system functions. The lack of proper authentication mechanisms makes it possible for attackers to exploit this flaw without prior credentials, leading to potential system compromise. (CVSS v4 score: 9.3, “critical”)
  • CVE-2024-38645 – Server-side request forgery (SSRF) vulnerability that could enable remote attackers with authentication credentials to send crafted requests that manipulate server-side behavior, potentially exposing sensitive application data.

QNAP has resolved these issues in Notes Station 3 version 3.9.7 and recommends users update to this version or later to mitigate the risk. Instructions on updating are available in this bulletin.

The other two issues listed in the same bulletin, CVE-2024-38644 und CVE-2024-38646, are high-severity (CVSS v4 score: 8.7, 8.4) command injection and unauthorized data access problems that require user-level access to exploit.

QuRouter flaws

The third critical flaw QNAP addressed on Saturday is CVE-2024-48860, impacting QuRouter 2.4.x products, QNAP’s line of high-speed, secure routers.

The flaw, rated 9.5 “critical” according to CVSS v4, is an OS command injection flaw that could allow remote attackers to execute commands on the host system.

QNAP also fixed a second, less severe command injection problem tracked as CVE-2024-48861, with both issues addressed in QuRouter version 2.4.3.106.

Other QNAP fixes

Other products that received important fixes this weekend are QNAP AI Core (AI engine), QuLog Center (log management tool), QTS (standard OS for NAS devices), and QuTS Hero (advanced version of QTS).

Here’s a summary of the most important flaws that were fixed in those products, with a CVSS v4 rating between 7.7 and 8.7 (high).

  • CVE-2024-38647: Information exposure problem that could allow remote attackers to gain access to sensitive data and compromise system security. The flaw affects QNAP AI Core version 3.4.x and has been resolved in version 3.4.1 and later.
  • CVE-2024-48862: Link-following flaw that could allow remote unauthorized attackers to traverse the file system and access or modify files. It impacts QuLog Center versions 1.7.x and 1.8.x, and was fixed in versions 1.7.0.831 and 1.8.0.888.
  • CVE-2024-50396 und CVE-2024-50397: Improper handling of externally controlled format strings, which could allow attackers to access sensitive data or modify memory. CVE-2024-50396 can be exploited remotely to manipulate system memory, while CVE-2024-50397 requires user-level access. Both vulnerabilities have been resolved in QTS 5.2.1.2930 and QuTS hero h5.2.1.2929.

QNAP customers are strongly advised to install the updates as soon as possible to remain protected against potential attacks.

As always, QNAP devices should never be connected directly to the Internet and should instead be deployed behind a VPN to prevent remote exploitation of flaws.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:19 pm, Juni 30, 2025
Wetter-Symbol 32°C
L: 30° | H: 34°
klarer Himmel
Luftfeuchtigkeit: 44 %
Druck: 1017 mb
Wind: 4 mph WSW
Windböe: 12 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 1%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:46 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
30° | 34°°C 0 mm 0% 10 mph 44 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
20° | 33°°C 0 mm 0% 11 mph 67 % 1016 mb 0 mm/h
Mi. Juli 02 10:00 pm
Wetter-Symbol
18° | 23°°C 0.38 mm 38% 12 mph 80 % 1023 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 6 mph 76 % 1028 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 11 mph 55 % 1027 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
29° | 32°°C 0 mm 0% 9 mph 44 % 1015 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
28° | 31°°C 0 mm 0% 10 mph 41 % 1015 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
24° | 27°°C 0 mm 0% 2 mph 43 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
23° | 23°°C 0 mm 0% 4 mph 54 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 4 mph 66 % 1014 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
24° | 24°°C 0 mm 0% 7 mph 67 % 1015 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
27° | 27°°C 0 mm 0% 5 mph 52 % 1015 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 4 mph 35 % 1014 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,680.30
-0.67%
Ethereum(ETH)
€2,101.03
0.53%
Fesseln(USDT)
€0.85
-0.01%
XRP(XRP)
€1.86
-0.47%
Solana(SOL)
€128.58
-1.03%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.140115
-0.44%
Shiba Inu(SHIB)
€0.000009
-2.19%
Pepe(PEPE)
€0.000009
-0.30%
Nach oben scrollen