Blog | G5 Cyber Security

Researchers warn of QNAP NAS attacks in the wild

Hackers target QNAP NAS devices running multiple firmware versions vulnerable to a remote code execution (RCE) flaw. Qihoo 360s Network Security Research Lab (360 Netlab) the attackers are exploiting the remote command execution vulnerability due to a command injection issue. The issue resides in the CGI program that is used when user logout to select the corresponding logout function based on the field name in the Cookie.ogle. The fix proposed by the vendor replaced the function used to run the command strings.”]

Source: https://securityaffairs.co/wordpress/107750/hacking/qnap-nas-attacks.html

Exit mobile version