Critical QNAP Vulnerability: CVE-2022-27596


Userlevel 7
Badge +13

Morning y’all!

Yesterday was released a new CVE with a 9.8 critical score for QNAP devices.

https://nvd.nist.gov/vuln/detail/CVE-2022-27596

Hackers can exploit this SQL injection vulnerability (CVE-2022-27596) to inject malicious code into unpatched, Internet-exposed QNAP devices in simple attacks by unauthenticated malicious actors without user interaction.

QNAP recommends upgrading impacted devices (running QTS 5.0.1 and QuTS hero h5.0.1) to the latest versions (QTS 5.0.1.2234 build 20221201 or later and QuTS hero h5.0.1.2248 build 20221215 or later) to protect against attacks, but if you can’t update right now, disable port forwarding to that device and disable the UPnP function of the QNAP NAS.

As is not yet being exploited and no proof-of-concept exploit code was shared online, there's still time to patch these vulnerable NAS devices.

Vulnerable QNAP NAS devices by country (Censys)

Besides updating ASAP, it's also recommended not to expose NAS devices online to prevent remote exploitation. QNAP has previously recommended disabling port forwarding, UPnP, SSH and Telnet connections, changing system port numbers, changing device passwords, and enabling IP and account access protection.


7 comments

Userlevel 7
Badge +11

Thanks for share @marcofabbri. I have a lot of customers using QNAP on backup environment.

Time to update!

Userlevel 7
Badge +13

Thanks for share @marcofabbri. I have a lot of customers using QNAP on backup environment.

Time to update!

Yup, QNAP is largely used in Italy territory too, and unfortunately CVEs on QNAP pop up too often

Userlevel 7
Badge +20

Interesting as I have never used QNAP.  Good to see there is a fix.

Userlevel 7
Badge +13

Interesting as I have never used QNAP.  Good to see there is a fix.

Woah really?? 😂

Userlevel 7
Badge +8

Thanks for share @marcofabbri. I have a lot of customers using QNAP on backup environment.

Time to update!

😱

Userlevel 7
Badge +8

Interesting as I have never used QNAP.  Good to see there is a fix.

Synology for the Win, but only SOHO

Userlevel 7
Badge +20

Interesting as I have never used QNAP.  Good to see there is a fix.

Synology for the Win, but only SOHO

I have Synology DS920+ with expansion at home for my lab.  😋

Comment