A new vulnerability has been disclosed for the QTS operating system used by QNAP storage devices. This vulnerability allows unauthenticated remote OSX users to potentially read and write arbitrary files. As AFP is disabled by default, this vulnerability would only affect users who have enabled this protocol. The vulnerability exists in firmware prior to 4.1.4 Build 0910 and 4.2.0 RC2 (Build 0910) If you are using an affected version, you should immediately upgrade to the latest version.”]

