
CVE-2024-27130是影响QNAP网络附加存储(NAS)设备的一个严重漏洞。该漏洞源于QTS操作系统中share.cgi脚本的No_Support_ACL函数中不安全地使用strcpy函数,导致堆栈缓冲区溢出。攻击者可以利用此漏洞,通过精心构造的请求在目标系统上执行任意代码,进而完全控制受影响的设备。
CVE-2024-27130 is a critical vulnerability affecting QNAP Network Attached Storage (NAS) devices. The flaw originates from the unsafe use of the strcpy function in the No_Support_ACL function of the share.cgi script within the QTS operating system, leading to a stack buffer overflow. An attacker can exploit this vulnerability by sending a specially crafted request to execute arbitrary code on the target system, thereby gaining full control over the affected device.
The impact of this vulnerability is mainly reflected in the following aspects:
Remote Code Execution (RCE): An unauthenticated attacker can remotely execute arbitrary code over the network, leading to complete system compromise.
Data Leakage and Tampering: Attackers may access, modify, or delete sensitive data stored on the NAS device.
Service Disruption: Malicious actions could disrupt the device's services, affecting business continuity.
QNAP has fixed this vulnerability in QTS 5.1.7.2770 build 20240520 and later versions. Users are advised to update their systems as soon as possible to prevent potential risks.