Multiple critical vulnerabilities in QNAP NAS devices, including security restriction bypass, remote code execution, denial of service, information disclosure, and privilege escalation, can be exploited by a remote attacker. Affected systems include QVP 2.7.1, QuTS cloud c5.2.8, QTS version 5.2.7, and QuTS hero h5.2.8. QNAP has released fixes detailed in security advisory QSA-26-10, which administrators must apply immediately.
Multiple vulnerabilities were identified in QNAP NAS. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, remote code execution, denial of service condition, sensitive information disclosure and elevation of privilege on the targeted system. Impact Denial of Service Information Disclosure Elevation of Privilege Remote Code Execution Security Restriction Bypass System / Technologies affected QVP 2.7.1 QuTS cloud c5.2.8 QTS version 5.2.7 QuTS hero h5.2.8 Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://www.qnap.com/en/security-advisory/qsa-26-10