Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-27130 PoC — QTS, QuTS hero

Source
Associated Vulnerability
Title: QTS, QuTS hero (CVE-2024-27130)
Description:A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later
Description
CVE-2024-27130是影响QNAP网络附加存储(NAS)设备的一个严重漏洞。该漏洞源于QTS操作系统中share.cgi脚本的No_Support_ACL函数中不安全地使用strcpy函数,导致堆栈缓冲区溢出。攻击者可以利用此漏洞,通过精心构造的请求在目标系统上执行任意代码,进而完全控制受影响的设备。 
Readme
# CVE-2024-27130-poc
CVE-2024-27130是影响QNAP网络附加存储(NAS)设备的一个严重漏洞。该漏洞源于QTS操作系统中`share.cgi`脚本的`No_Support_ACL`函数中不安全地使用`strcpy`函数,导致堆栈缓冲区溢出。攻击者可以利用此漏洞,通过精心构造的请求在目标系统上执行任意代码,进而完全控制受影响的设备。 

该漏洞的危害主要体现在以下方面:

- **远程代码执行(RCE)**:未经身份验证的攻击者可通过网络远程执行任意代码,导致系统被完全控制。

- **数据泄露和篡改**:攻击者可能访问、修改或删除存储在NAS设备上的敏感数据。

- **服务中断**:恶意操作可能导致设备服务中断,影响业务连续性。

QNAP已在QTS 5.1.7.2770 build 20240520及之后的版本中修复了此漏洞。建议用户尽快更新系统,以防范潜在风险。  
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →