CVE-2017-6361
Description
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
In plain language
AI Worth attentionCVE-2017-6361 is a serious remote “break-in” flaw in QNAP QTS before 4.2.4 Build 20170313 that can let an attacker run commands on the device without logging in; act now if your QNAP is reachable from the network.
CVE-2017-6361 describes a remote, unauthenticated command-execution flaw (CWE-78) in QNAP QTS before 4.2.4 Build 20170313, enabling attackers to run arbitrary system commands over the network without needing credentials or user interaction.
What to do now
- Check your QNAP device firmware version and confirm it is QTS before 4.2.4 Build 20170313.
- If it is affected, upgrade QTS to 4.2.4 Build 20170313 or later using QNAP’s official firmware update process.
- Verify the device is not exposed to the public internet (no direct port-forwarding/UPnP), and restrict access to only your office/VPN networks.
- Re-check after the update that the QTS version shows as 4.2.4 Build 20170313 or later.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-6361 and every CVE in our database. Create a free account — no credit card required.
Create Free Account