Taiwan-based network-attached storage (NAS) maker QNAP has released security patches for multiple vulnerabilities that could allow attackers to inject and execute malicious code and commands remotely on vulnerable NAS devices.
Three of the security flaws fixed today by QNAP are high severity stored cross-site scripting (XSS) vulnerabilities (tracked as CVE-2021-34354, CVE-2021-34356, and CVE-2021-34355) affect devices running unpatched Photo Station software (releases before 5.4.10, 5.7.13, or 6.0.18).
QNAP also patched a stored XSS Image2PDF flaw impacting devices running software versions released before Image2PDF 2.1.5.
Also Read: Cost of GDPR Compliance for Singapore Companies
Stored XSS attacks allow threat actors to inject malicious code remotely, permanently storing it on the targeted servers following successful exploitation.
The company also addressed a command injection bug (CVE-2021-34352) affecting some QNAP end-of-life (EOL) devices running the QVR IP video surveillance software that helps attackers run arbitrary commands.
Successful attacks exploiting the CVE-2021-34352 flaw could lead to the complete takeover of compromised NAS devices.
Three other QVR flaws were also patched on Monday, as disclosed by QNAP in a security advisory rated with a critical severity rating.
Given that QNAP NAS devices have been under a constant barrage of attacks the last couple of years, customers should immediately update both apps to the latest available releases as soon as possible.
To update Photo Station or Image2PDF to the latest version on your NAS, you need to go through the following procedure:
To update the QVR surveillance software, follow these steps:
QNAP warned in September 2020 of a surge in ransomware attacks encrypting files on publicly exposed NAS storage devices.
Also Read: 7 Key Principles of Privacy by Design that Businesses should adopt
As BleepingComputer reported at the time, QNAP customers’ devices were being hit by AgeLocker ransomware which was targeting older unpatched versions of Photo Station, an app used to upload photos, create albums, and view them remotely.
QNAP also warned of eCh0raix ransomware attacks attempting to exploit flaws in the Photo Station app starting with June 2020.