Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-27130 PoC — QNAP Systems QTS和QuTS hero 安全漏洞

Source
Associated Vulnerability
Title:QNAP Systems QTS和QuTS hero 安全漏洞 (CVE-2024-27130)
Description:QNAP Systems QTS和QNAP Systems QuTS hero都是中国威联通科技(QNAP Systems)公司的产品。QNAP Systems QTS是一个入门到中阶QNAP NAS 使用的操作系统。QNAP Systems QuTS hero是一个操作系统。 QNAP Systems QTS和QuTS hero存在安全漏洞,该漏洞源于未检查输入大小的缓冲区副本,可能允许经过身份验证的用户通过网络执行代码。
Description
PoC for CVE-2024-27130
Readme
# CVE-2024-27130

A Proof of Concept developed by @watchTowr to exploit stack overflow vulnerability to obtain RCE on a vulnerable QNAP device.

# Follow the [watchTowr](http://watchTowr.com) Labs Team for our Security Research

- https://labs.watchtowr.com/
- https://twitter.com/watchtowrcyber
File Snapshot

[4.0K] /data/pocs/1956cf48ffaebfceaf3e8fd71425692c2dd31520 ├── [1.8K] poc_CVE-2024-27130.py ├── [1.5K] qnap.py └── [ 295] README.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.