QNAP addresses CVE-2024-50389 in QuRouter

QNAP addresses CVE-2024-50389 in QuRouter


QNAP has addressed a critical zero-day vulnerability in its QuRouter network security appliance, exploited by security researchers during the recent Pwn2Own hacking contest in Ireland.

The vulnerability, tracked as CVE-2024-50389 with a CVSS score of 7.8, allowed the Viettel Cyber Security team to compromise a QuRouter devices

QNAP released patches for the affected QuRouter 2.4.x versions, urging users to update to version 2.4.5.032 or later immediately and acknowledged Viettel Cyber Security for responsibly disclosing the vulnerability.

Advertisements

This patch release follows two other zero-day vulnerabilities patched by QNAP last week, also discovered by the same team during Pwn2Own:

  • CVE-2024-50388: A flaw in the HBS 3 Hybrid Backup Sync solution that allowed attackers to execute arbitrary commands on a TS-464 NAS device.
  • CVE-2024-50387: A critical SQL injection vulnerability in QNAP’s SMB Service.

QNAP has provided clear instructions for updating to the latest firmware version:

  1. Log in to your QuRouter.
  2. Go to Firmware.
  3. Select Update now.
  4. Select Latest.
  5. Click Apply and confirm.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.