QNAP.QTS.quick.cgi.Remote.Command.Injection

description-logoDescription

This indicates an attack attempt to exploit a Command Injection vulnerability in QNAP QTS, QuTS hero and QuTScloud.
The vulnerability is due to an error in the application when handling a crafted HTTP request. A remote attacker may be able to exploit this to execute arbitrary code within the context of the application.

affected-products-logoAffected Products

QTS 5.x before 5.1.5.2645 build 20240116
QTS 4.5.x, 4.4.x before QTS 4.5.4.2627 build 20231225
QTS 4.3.6, 4.3.5 before QTS 4.3.6.2665 build 20240131
QTS 4.3.4 before QTS 4.3.4.2675 build 20240131
QTS 4.3.x before QTS 4.3.3.2644 build 20240131
QTS 4.2.x before QTS 4.2.6 build 20240131
QuTS hero h5.1.x before QuTS hero h5.1.5.2647 build 20240118
QuTS hero h5.0.1 before QuTS hero h5.1.5.2647 build 20240118
QuTS hero h5.0.0 before QuTS hero h5.1.5.2647 build 20240118
QuTS hero h4.x before QuTS hero h4.5.4.2626 build 20231225
QuTScloud c5.x before QuTScloud c5.1.5.2651

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the latest update from the vendor.
https://www.qnap.com/en/security-advisory/qsa-23-57

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2024-03-25 27.754 Default_action:pass:drop
2024-03-06 27.744