QNAP has released critical security updates over the weekend to address multiple vulnerabilities affecting its NAS systems and routers. These flaws include three “critical” severity issues that could allow unauthorized system access and remote code execution. Users are strongly urged to update their devices immediately.
Two critical flaws were found in Notes Station 3, a collaboration and note-taking app widely used in QNAP NAS devices:
QNAP has fixed these issues in Notes Station 3 version 3.9.7. Users are advised to update immediately to mitigate risks. Full update instructions are available in QNAP’s official security bulletin.
Additional vulnerabilities, CVE-2024-38644 and CVE-2024-38646, rated as “high severity,” involve command injection and unauthorized data access. These require user-level access to exploit.
A critical vulnerability, CVE-2024-48860, impacts QNAP’s QuRouter 2.4.x devices. This OS command injection flaw could allow remote attackers to execute commands on the host system.
Another less severe issue, CVE-2024-48861, also involving command injection, has been patched. Both issues are resolved in QuRouter version 2.4.3.106, and QNAP recommends immediate updates.
QNAP addressed additional vulnerabilities across its ecosystem, including:
Trending: Recon Tool: emailFinder
QNAP urges all users to install these updates as soon as possible to secure their systems against potential attacks.
Additionally:
By taking these precautions, users can mitigate risks and protect sensitive data from exploitation.
Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? If you want to express your idea in an article contact us here for a quote: [email protected]
Source: bleepingcomputer.com