CVE-2024-53691
massLink-Following File System Traversal in QNAP QTS and QuTS hero
CVE-2024-53691 is a link-following (CWE-59) vulnerability in QNAP's QTS and QuTS hero NAS operating systems that lets an attacker traverse the file system to unintended locations. It is triggered remotely over the network by an attacker who has already obtained user-level access to the device; no user interaction is required, and the lack of UI/privilege requirements in the CVSS 4.0 vector (8.7 High) means a low-privileged account is the main barrier. Successful exploitation carries high impact on confidentiality, integrity, and availability of the vulnerable system, allowing the attacker to read, modify, or affect files outside the intended scope via manipulated links. Any QNAP NAS running QTS or QuTS hero in the affected 5.1.x/5.2.x branches prior to the fixed builds is affected, with internet-exposed devices and those granting accounts to third parties at greatest risk. There is no known public proof-of-concept and the flaw is not yet in CISA's KEV catalog, but a 20.1% EPSS score (97th percentile) indicates a meaningful chance of exploitation within 30 days.
What to do: Upgrade to QTS 5.1.8.2823 build 20240712 (or later), QTS 5.2.0.2802 build 20240620 (or later), QuTS hero h5.1.8.2823 build 20240712 (or later), or QuTS hero h5.2.0.2802 build 20240620 (or later). Until patched, restrict or firewall web/admin access to trusted networks, avoid exposing the NAS interface directly to the internet, and audit user accounts since exploitation requires user-level credentials. Monitor QNAP advisories for evidence of in-the-wild exploitation given the elevated EPSS score.
| QNAP QTS | 5.1.x versions prior to 5.1.8.2823 build 20240712 |
| QNAP QTS | 5.2.x versions prior to 5.2.0.2802 build 20240620 |
| QNAP QuTS hero | h5.1.x versions prior to h5.1.8.2823 build 20240712 |
| QNAP QuTS hero | h5.2.x versions prior to h5.2.0.2802 build 20240620 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QTS 5.2.0.2802 build 20240620 and later QuTS hero h5.1.8.2823 build 20240712 and later QuTS hero h5.2.0.2802 build 20240620 and later
- Vendors
- qnap
- Products
- qts, quts hero
- Weakness
- CWE-59
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.