Stephen Fewer

Stephen Fewer

@stephenfewer · Twitter ·

QNAP have patched an unauthenticated command injection vuln we reported, CVE-2023-47218, affecting QTS and QuTS Hero based systems. Vuln is in a component quick.cgi, which helps configure uninitialized systems. Read our disclosure here: https://www.rapid7.com/blog/post/2024/02/13/cve-2023-47218-qnap-qts-and-quts-hero-unauthenticated-command-injection-fixed/