The 360Netlab Threat Detection System reported attacks targeting the widely used QNAP NAS devices through the unauthorized remote command execution vulnerability (CVE-2020-2506 & CVE-2019-2507) upon successful attack, the attacker will gain root privilege on the device and perform malicious mining activities. The report says there is currently no publicly available PoC for the vulnerability, also according to the vendors request, the technical details of the vulnerability is not disclosed. Experts speculate that there are still hundreds of thousands of online QNap NAS devices with vulnerability.”]
Source: https://gbhackers.com/crypto-miner-campaign-targets-qnap-nas/

