PT-2024-9843 · Qnap · Qnap Smb Service

Yingmuo

·

Published

2024-10-30

·

Updated

2025-12-08

·

CVE-2024-50387

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: QNAP SMB Service versions prior to 4.15.002 QNAP SMB Service h versions prior to h4.15.002
Description: A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. The vulnerability is related to the lack of protection of the SQL query structure. It has been exploited in recent hacking contests, showcasing high-risk attack vectors, and may allow unauthorized access to QNAP NAS devices and sensitive data.
Recommendations: For QNAP SMB Service versions prior to 4.15.002, update to version 4.15.002 or later. For QNAP SMB Service h versions prior to h4.15.002, update to version h4.15.002 or later. As a temporary workaround, consider restricting access to the SMB Service until a patch is applied.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-11621
CVE-2024-50387
ZDI-25-759

Affected Products

Qnap Smb Service