QNAP flickt zweiten Zero-Day, der bei Pwn2Own ausgenutzt wurde, um Root zu erhalten

Teilen:

QNAP has released security patches for a second zero-day bug exploited by security researchers during last week’s Pwn2Own hacking contest.

This critical SQL injection (SQLi) vulnerability, tracked as CVE-2024-50387, was found in QNAP’s SMB Service and is now fixed in versions 4.15.002 or later and h4.15.002 and later.

The zero-day flaw was patched one week after allowing YingMuo (working with the DEVCORE Internship Program) to get a root shell and take over a QNAP TS-464 NAS device at Pwn2Own Ireland 2024.

On Tuesday, the company fixed another zero-day in its HBS 3 Hybrid Backup Sync disaster recovery and data backup solution, exploited by Viettel Cyber Security’s team at Pwn2Own to execute arbitrary commands and hack a TS-464 NAS device.

Team Viettel won Pwn2Own Ireland 2024 after four days of competition, during which more than $1 million in prizes were awarded to hackers who demonstrated over 70 unique zero-day vulnerabilities.

While QNAP patched both vulnerabilities within a week, vendors usually take their time to release security patches after the Pwn2Own contest, given that they have 90 days until Trend Micro’s Zero Day Initiative releases details on bugs disclosed during the contest.

QNAP DEVCORE zero-day

To update the software on your NAS device, log in to QuTS hero or QTS as an administrator, go to the App Center, search for “SMB Service,” and click “Update.” This button will not be available if the software is already up-to-date.

Patching quickly is highly recommended, as QNAP devices are popular targets for cybercriminals because they’re commonly used for backing up and storing sensitive personal files. This makes them easy targets for installing information-stealing malware and the perfect leverage for forcing victims to pay a ransom to get back their data.

For instance, in June 2020, QNAP warned of eCh0raix ransomware attacks, which exploited Photo Station app vulnerabilities to hack into and encrypt QNAP NAS devices.

QNAP also alerted customers in September 2020 of AgeLocker ransomware attacks targeting publicly exposed NAS devices running older and vulnerable Photo Station versions. In June 2021, eCh0raix (QNAPCrypt) returned with new attacks exploiting known vulnerabilities and brute-forcing NAS accounts using weak passwords.

Other recent attacks targeting QNAP devices include DeadBolt, Checkmate, and eCh0raix ransomware campaigns, which abused various security vulnerabilities to encrypt data on Internet-exposed NAS devices.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:51 am, Juni 27, 2025
Wetter-Symbol 20°C
L: 19° | H: 21°
wenige Wolken
Luftfeuchtigkeit: 66 %
Druck: 1020 mb
Wind: 9 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:45 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 21°°C 0 mm 0% 13 mph 68 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 29°°C 0 mm 0% 11 mph 91 % 1025 mb 0 mm/h
So. Juni 29 10:00 pm
Wetter-Symbol
19° | 31°°C 0 mm 0% 8 mph 76 % 1025 mb 0 mm/h
Mo. Juni 30 10:00 pm
Wetter-Symbol
21° | 34°°C 0.2 mm 20% 8 mph 64 % 1021 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
21° | 33°°C 0 mm 0% 11 mph 68 % 1016 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
19° | 20°°C 0 mm 0% 9 mph 66 % 1020 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
22° | 25°°C 0 mm 0% 12 mph 61 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
25° | 27°°C 0 mm 0% 13 mph 48 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 13 mph 39 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 11 mph 68 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 9 mph 85 % 1021 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 9 mph 91 % 1022 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 8 mph 82 % 1023 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,342.10
-1.03%
Ethereum(ETH)
€2,093.68
-1.71%
Fesseln(USDT)
€0.86
-0.02%
XRP(XRP)
€1.79
-4.47%
Solana(SOL)
€121.29
-2.27%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.137985
-1.97%
Shiba Inu(SHIB)
€0.000009
-3.38%
Pepe(PEPE)
€0.000008
-2.59%
Nach oben scrollen