QNAP addressed a critical flaw that allows compromising NAS devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-28799 | Improper Authorization in QNAP HBS 3 Allows Remote Login to NAS Devices CVE-2021-28799 is a critical improper authorization flaw (CWE-285, CVSS 9.8) in HBS 3 (Hybrid Backup Sync), the backup application bundled with QNAP NAS firmware. Because the weakness is reachable over the network with no privileges and no user interaction, a remote attacker who can reach an affected NAS can bypass authorization and log in to the device. An attacker gaining this unauthorized login obtains remote access to the NAS, which threat actors have leveraged in ransomware campaigns against QNAP devices. Anyone running HBS 3 on QTS 4.3.3, 4.3.4, 4.3.6 or 4.5.2, QuTS hero h4.5.1, or QuTScloud c4.5.1-c4.5.4 at versions below the listed fixes is affected, while HBS 2 and HBS 1.3 are not affected. The flaw is in the wild: it was added to CISA's KEV on 2022-03-31 with known ransomware use, EPSS puts 30-day exploitation probability at 78.3% (top percentile), and public reporting around this period describes ransomware waves (e.g., Qlocker, eCh0raix) infecting hundreds of QNAP NAS devices within days. Do: Update HBS 3 to the fix for your OS: v16.0.0415 on QTS 4.5.2, v3.0.210412 on QTS 4.3.6, v3.0.210411 on QTS 4.3.4/4.3.3, and v16.0.0419 on QuTS hero h4.5.1 and QuTScloud c4.5.1~c4.5.4. Until patched, keep the NAS and its web services off the direct internet (disable router port forwarding/UPnP to the NAS) and review devices for signs of compromise. Given the KEV listing and known ransomware use, prioritize internet-reachable NAS devices. | 9.8 | 78% | KEV ransomware |
| mass≈1M+ QNAP NAS devices plausibly run an affected HBS 3 build (the app ships bundled with the affected QTS/QuTS releases), with hundreds of thousands of QNAP NAS… | |
| CVE-2021-28809 | An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later NVD description · AI analysis pending | 9.8 | 16% |
| — |
Full article423 words · extracted from securityaffairs.com · click to collapse

Taiwanese vendor QNAP addressed a critical flaw, tracked as CVE-2021-28809, that could be exploited to compromise vulnerable NAS devices.
Taiwanese vendor QNAP fixed a critical vulnerability, tracked as CVE-2021-28809, that could be exploited by attackers to compromise vulnerable NAS devices.
The vulnerability affects certain legacy versions of HBS 3 Hybrid Backup Sync, it was reported to the vendor by Ta-Lun Yen of TXOne IoT/ICS Security Research Labs.
“An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3 (Hybrid Backup Sync). If exploited, this vulnerability allows attackers to compromise the security of the operating system.” states the security advisory published by the company.
The vendor addressed the flaw in the following versions of HBS 3:
- QTS 4.3.6: HBS 3 v3.0.210507 and later
- QTS 4.3.4: HBS 3 v3.0.210506 and later
- QTS 4.3.3: HBS 3 v3.0.210506 and later
QNAP devices running QTS 4.5.x with HBS 3 v16.x are not affected.
In May, the Taiwanese vendor warned its customers of updating the HBS 3 disaster recovery app running on their Network Attached Storage (NAS) devices to prevent Qlocker ransomware infections.
At the end of April, experts warned of a new strain of ransomware named Qlocker that was infecting hundreds of QNAP NAS devices on daily bases.
The threat actors behind the attacks are exploiting an improper authorization vulnerability, tracked as CVE-2021-28799, that could allow them to log in to a NAS device
“A ransomware campaign targeting QNAP NAS began the week of April 19th, 2021. The ransomware known as Qlocker exploits CVE-2021-28799 to attack QNAP NAS running certain versions of HBS 3 (Hybrid Backup Sync).” reads the security advisory published by the vendor.
The attacks were first spotted on April 20, and the number of infections has skyrocketed into the hundreds per day, according to statistics provided by Michael Gillespie, the creator of ransomware identification service ID-Ransomware.
In May, QNAP also warned customers of threat actors that were targeting its Network Attached Storage (NAS) devices with eCh0raix ransomware and exploiting a Roon Server zero-day vulnerability.
Early May, the Taiwanese vendor warned its customers of
Last week, QNAP warned customers of threat actors that are targeting its Network Attached Storage (NAS) devices with eCh0raix ransomware attacks and exploiting a Roon Server zero-day vulnerability.
Early this month, the Taiwanese vendor warned its customers of an ongoing wave of AgeLocker ransomware attacks on their NAS devices
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, QNAP)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/119750/hacking/qnap-nas-critical-flaw.html