QNAP NAS devices under ransomware attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-2509 | Command Injection RCE in QNAP Network-Attached Storage (NAS) QNAP Network-Attached Storage (NAS) devices contain a command injection vulnerability (CWE-77/CWE-78) in which unsanitized input is passed to an operating-system command shell, allowing remote attackers to run arbitrary commands. The flaw is reachable over the network through the NAS device's software interfaces, so an attacker who can reach a vulnerable device can trigger the injection and achieve remote code execution. Successful exploitation gives an attacker control of the NAS, including access to stored data and a potential foothold for lateral movement or ransomware, though CISA has not confirmed ransomware use in this case. Any organization running an affected QNAP NAS device is exposed, especially where the management interface is internet-facing; exact affected version ranges are not stated in the available data and should be taken from QNAP's security advisory. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-11, indicating exploitation has been observed in the wild, and its 33.4% EPSS score (98th percentile) signals elevated near-term exploitation risk, although no public PoC is known. Do: Apply the vendor's firmware/OS updates per QNAP's security advisory, as this is the required action under CISA's KEV catalog. Until patched, remove direct internet exposure of NAS management interfaces and restrict access via firewall rules or VPN. Because exploitation has been observed in the wild, check NAS logs for unexpected commands, processes, or logins even after updating. | 9.8 | 33% | KEV |
| massHundreds of thousands of internet-exposed QNAP NAS devices (total installed base in the millions of units) | |
| CVE-2020-36195 | An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the Media Streaming add-on. QTS 4.3.3: Media Streaming add-on 430.1.8.10 and later QTS 4.3.6: Media Streaming add-on 430.1.8.8 and later QTS 4.4.x and later: Multimedia Console 1.3.4 and later We have also fixed this vulnerability in the following versions of QTS 4.3.3 and QTS 4.3.6, respectively: QTS 4.3.3.1624 Build 20210416 or later QTS 4.3.6.1620 Build 20210322 or later NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2021-28799 | Improper Authorization in QNAP HBS 3 Allows Remote Login to NAS Devices CVE-2021-28799 is a critical improper authorization flaw (CWE-285, CVSS 9.8) in HBS 3 (Hybrid Backup Sync), the backup application bundled with QNAP NAS firmware. Because the weakness is reachable over the network with no privileges and no user interaction, a remote attacker who can reach an affected NAS can bypass authorization and log in to the device. An attacker gaining this unauthorized login obtains remote access to the NAS, which threat actors have leveraged in ransomware campaigns against QNAP devices. Anyone running HBS 3 on QTS 4.3.3, 4.3.4, 4.3.6 or 4.5.2, QuTS hero h4.5.1, or QuTScloud c4.5.1-c4.5.4 at versions below the listed fixes is affected, while HBS 2 and HBS 1.3 are not affected. The flaw is in the wild: it was added to CISA's KEV on 2022-03-31 with known ransomware use, EPSS puts 30-day exploitation probability at 78.3% (top percentile), and public reporting around this period describes ransomware waves (e.g., Qlocker, eCh0raix) infecting hundreds of QNAP NAS devices within days. Do: Update HBS 3 to the fix for your OS: v16.0.0415 on QTS 4.5.2, v3.0.210412 on QTS 4.3.6, v3.0.210411 on QTS 4.3.4/4.3.3, and v16.0.0419 on QuTS hero h4.5.1 and QuTScloud c4.5.1~c4.5.4. Until patched, keep the NAS and its web services off the direct internet (disable router port forwarding/UPnP to the NAS) and review devices for signs of compromise. Given the KEV listing and known ransomware use, prioritize internet-reachable NAS devices. | 9.8 | 78% | KEV ransomware |
| mass≈1M+ QNAP NAS devices plausibly run an affected HBS 3 build (the app ships bundled with the affected QTS/QuTS releases), with hundreds of thousands of QNAP NAS… |
Full article485 words · extracted from helpnetsecurity.com · click to collapse
QNAP NAS device owners are once again under attack by ransomware operators, who are exploiting a recently fixed vulnerability to lock data on vulnerable devices by using the 7-Zip open-source file archiver utility.

According to Lawrence Abrams, the ransomware gang has managed to “earn” $260,000 in five days, as many unfortunate victims decided to pay the ransom of 0.01 Bitcoins (around $550) to receive the password that would unlock their files.
What happened?
On April 16, QNAP has anounced that they have fixed:
- CVE-2020-2509, a command injection vulnerability in QTS and QuTS hero, and
- CVE-2020-36195, an SQL injection vulnerability affecting QNAP NAS running Multimedia Console or the Media Streaming add-on
On April 22, the company anounced that they have also resolved CVE-2021-28799, an improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 Hybrid Backup Sync, on April 16.
QNAP initially believed that the ransomware operation called Qlocker exploited CVE-2020-36195 (the SQL injection flaw) to gain access to internet-connected NAS devices and lock users’ data, but it turned out to be CVE-2021-28799 (the improper authorization vulnerability, i.e., a backdoor account).
In any case, the attackers likely managed to compromise thousands of devices belonging to both consumers and small-to-medium businesses (SMBs) and lock the data found on them. Abrams has calculated that over 500 of the victims have paid the ransom.
Some 50 victims have been lucky to have been helped by security researcher Jack Cable to recover their files without a password due to a bug in 7-Zip. Unfortunately, that window of opportunity didn’t last long:
Update: it looks like this may have been fixed by the ransomware operators, unfortunately. I apologize if I was not able to get to yours before it was fixed. In total decrypted around 50 keys worth $27k.
— Jack Cable (@jackhcable) April 22, 2021
What now?
Those lucky QNAP NAS owners that have not yet been hit by the attackers are advised to implement the offered updates to stymie these and other ransomware gangs.
They should follow the advice offered by QNAP, as well as implement best practices for enhancing the devices’ security, since they are often targeted by attackers.
UPDATE (April 30, 2021, 05:00 a.m. PT):
“The QNAP security team has detected suspicious ransomware in the wild known as AgeLocker, which has the potential to affect QNAP NAS devices,” QNAP warned on Thursday, but did not say which vulnerabilities the attackers are exploiting.
“To secure your device, we strongly recommend regularly updating QTS or QuTS hero and all installed applications to their latest versions to benefit from vulnerability fixes. You can check the product support status to see the latest updates available to your NAS model. To further secure your device, do not expose your NAS to the internet. If you must connect your NAS to the internet, we highly recommend using a trusted VPN or a myQNAPcloud link.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/04/26/qnap-nas-ransomware/