Rewterz
Rewterz Threat Alert – FormBook Malware – Active IOCs
June 15, 2021
Rewterz
Rewterz Threat Alert – Agent Tesla Malware – Active IOCs
June 16, 2021

Rewterz Threat Advisory – CVE-2021-28814 – QNAP Releases Improper Access Control Vulnerability

Severity

High

Analysis Summary

CVE-2021-28814

An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software.

Impact

  • Remote Code Execution
  • Unauthorized Access

Affected Vendors

QNAP

Affected Products

  • All QNAP NAS

Remediation

  1. Log on to QTS or QuTS hero as administrator.
  2. Open the App Center, and then click. A search box appears.
  3. Type “Helpdesk”, and then press ENTER. The Helpdesk application appears in the search results.
  4. Click Update. A confirmation message appears. Note: The Update button is not available if you are using the latest version.
  5. Click OK.
  6. The application is updated.