Back to all
2021-05-12

QNAP Storage - Backdoor SID RCE

ZUSOART ID
CVE-2021-28799
CVE ID
CVE-2021-28799
Vulnerability Type
Improper Authorization Vulnerability
CVSS 4.0 Base
10
Description

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. )

If exploited, the vulnerability allows remote attackers to log in to a device.

We have already fixed this vulnerability in the following versions of HBS 3:

QTS 4.5.2: HBS 3 v16.0.0415 and later
QTS 4.3.6: HBS 3 v3.0.210412 and later
QTS 4.3.3 and 4.3.4: HBS 3 v3.0.210411 and later
QuTS hero h4.5.1: HBS 3 v16.0.0419 and later
QuTScloud c4.5.1~c4.5.4: HBS 3 v16.0.0419 and later
QNAP NAS running HBS 2 and HBS 1.3 are not affected.
Vendor
QNAP Systems, Inc.
Product
Category
Version affected
QNAP NAS running HBS 3
Before 2021/05/01
Mitigations

To fix the vulnerability, we recommend updating HBS 3 to the latest version.

Release date
2021-05-12
Credit

ZUSO ART