NA

CVE-2024-32766

Published: 26/04/2024 Updated: 26/04/2024

Vulnerability Summary

This vulnerability allows remote malicious users to escalate privileges on affected installations of QNAP TS-464 NAS devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the privWizard.cgi endpoint. The issue results from an exposed dangerous method. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.

Vulnerability Trend

Github Repositories

writeup and PoC for CVE-2024-32766 (QNAP) OS command injection, chained attack for auth bypass.

CVE-2024-32766-POC writeup and PoC for CVE-2024-32766 (QNAP) OS command injection, chained attack for auth bypass CVE-2024-32766 is an OS command injection vulnerablity which affects QNAP products Details: CVE-2024-32766 is an os command injection which can be triggered by sending specialy crafted [redacted] request to the [redacted] endpoint to reach the command injection p

writeup and PoC for CVE-2024-32766 QNAP OS command injection vulnerability.

CVE-2024-32766-POC writeup and PoC for CVE-2024-32766 QNAP OS command injection vulnerability CVE-2024-32766 is an OS command injection vulnerablity which affects QNAP products Details: CVE-2024-32766 is an os command injection which can be triggered by sending specialy crafted [redacted] request to the [redacted] endpoint to reach the command injection point we need to bypa

writeup and PoC for CVE-2024-32766 (QNAP) OS command injection and auth bypass

CVE-2024-32766-RCE writeup and PoC for CVE-2024-32766 (QNAP) OS command injection and auth bypass CVE-2024-32766 is an OS command injection vulnerablity which affects QNAP products Details: CVE-2024-32766 is an os command injection which can be triggered by sending specialy crafted [redacted] request to the [redacted] endpoint to reach the command injection point we need to b