Skip to main content

Critical QNAP Vulnerability: CVE-2022-27596


marcofabbri
Forum|alt.badge.img+13

Morning y’all!

Yesterday was released a new CVE with a 9.8 critical score for QNAP devices.

https://nvd.nist.gov/vuln/detail/CVE-2022-27596

Hackers can exploit this SQL injection vulnerability (CVE-2022-27596) to inject malicious code into unpatched, Internet-exposed QNAP devices in simple attacks by unauthenticated malicious actors without user interaction.

QNAP recommends upgrading impacted devices (running QTS 5.0.1 and QuTS hero h5.0.1) to the latest versions (QTS 5.0.1.2234 build 20221201 or later and QuTS hero h5.0.1.2248 build 20221215 or later) to protect against attacks, but if you can’t update right now, disable port forwarding to that device and disable the UPnP function of the QNAP NAS.

As is not yet being exploited and no proof-of-concept exploit code was shared online, there's still time to patch these vulnerable NAS devices.

Vulnerable QNAP NAS devices by country (Censys)

Besides updating ASAP, it's also recommended not to expose NAS devices online to prevent remote exploitation. QNAP has previously recommended disabling port forwarding, UPnP, SSH and Telnet connections, changing system port numbers, changing device passwords, and enabling IP and account access protection.

7 comments

wolff.mateus
Forum|alt.badge.img+11
  • Veeam Vanguard
  • 542 comments
  • February 2, 2023

Thanks for share @marcofabbri. I have a lot of customers using QNAP on backup environment.

Time to update!


marcofabbri
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 990 comments
  • February 2, 2023
wolff.mateus wrote:

Thanks for share @marcofabbri. I have a lot of customers using QNAP on backup environment.

Time to update!

Yup, QNAP is largely used in Italy territory too, and unfortunately CVEs on QNAP pop up too often


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8512 comments
  • February 2, 2023

Interesting as I have never used QNAP.  Good to see there is a fix.


marcofabbri
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 990 comments
  • February 2, 2023
Chris.Childerhose wrote:

Interesting as I have never used QNAP.  Good to see there is a fix.

Woah really?? πŸ˜‚


Link State
Forum|alt.badge.img+11
  • Veeam Legend
  • 613 comments
  • February 2, 2023
wolff.mateus wrote:

Thanks for share @marcofabbri. I have a lot of customers using QNAP on backup environment.

Time to update!

😱


Link State
Forum|alt.badge.img+11
  • Veeam Legend
  • 613 comments
  • February 2, 2023
Chris.Childerhose wrote:

Interesting as I have never used QNAP.  Good to see there is a fix.

Synology for the Win, but only SOHO


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8512 comments
  • February 2, 2023
Link State wrote:
Chris.Childerhose wrote:

Interesting as I have never used QNAP.  Good to see there is a fix.

Synology for the Win, but only SOHO

I have Synology DS920+ with expansion at home for my lab.  πŸ˜‹


Comment