← Back to browse · API

CVE-2024-53691

Severity
HIGH
CVSS
8.7
EPSS
0.20112
Risk score
41.84
CISA KEV
No
PoC
No
Published
2024-12-06
Modified
2025-01-24
First seen
2026-08-07
Aliases
EUVD-2024-52034, GHSA-6HFR-HXPF-C7M6
Products
QNAP Systems Inc.:QTS 5.1.x <5.1.8.2823 build 20240712, QNAP Systems Inc.:QTS 5.2.x <5.2.0.2802 build 20240620, QNAP Systems Inc.:QuTS hero h5.1.x <h5.1.8.2823 build 20240712, QNAP Systems Inc.:QuTS hero h5.2.x <h5.2.0.2802 build 20240620
Sources
euvd EUVD-2024-52034

Description

A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QTS 5.2.0.2802 build 20240620 and later QuTS hero h5.1.8.2823 build 20240712 and later QuTS hero h5.2.0.2802 build 20240620 and later

References