NA

CVE-2024-32766

Published: 26/04/2024 Updated: 26/04/2024

Vulnerability Summary

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

Vulnerability Trend

Github Repositories

writeup and PoC for CVE-2024-32766 (QNAP) OS command injection, chained attack for auth bypass.

CVE-2024-32766-POC writeup and PoC for CVE-2024-32766 (QNAP) OS command injection, chained attack for auth bypass CVE-2024-32766 is an OS command injection vulnerablity which affects QNAP products Details: CVE-2024-32766 is an os command injection which can be triggered by sending specialy crafted [redacted] request to the [redacted] endpoint to reach the command injection p

writeup and PoC for CVE-2024-32766 QNAP OS command injection vulnerability.

CVE-2024-32766-POC writeup and PoC for CVE-2024-32766 QNAP OS command injection vulnerability CVE-2024-32766 is an OS command injection vulnerablity which affects QNAP products Details: CVE-2024-32766 is an os command injection which can be triggered by sending specialy crafted [redacted] request to the [redacted] endpoint to reach the command injection point we need to bypa

writeup and PoC for CVE-2024-32766 (QNAP) OS command injection and auth bypass

CVE-2024-32766-RCE writeup and PoC for CVE-2024-32766 (QNAP) OS command injection and auth bypass CVE-2024-32766 is an OS command injection vulnerablity which affects QNAP products Details: CVE-2024-32766 is an os command injection which can be triggered by sending specialy crafted [redacted] request to the [redacted] endpoint to reach the command injection point we need to b