Vulnerability record · CVE-2017-6360 · published 23 March 2017
CVE-2017-6360: QNAP QTS OS command injection grants administrator privileges
Qnap · Qts
QNAP QTS before 4.2.4 Build 20170313 contains an OS command injection flaw (CWE-78) that lets attackers gain administrator privileges and obtain sensitive information. The advisory describes the vectors only as unspecified, so the exact injection point is not documented in this record. With a network-reachable, unauthenticated attack path and full confidentiality, integrity and availability impact, this is a severe pre-auth flaw in a widely deployed NAS operating system.
Description
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-authentication network command injection with full CIA impact, a public exploit, and very high EPSS probability makes this an urgent patch target despite no KEV listing.
What it is
QNAP QTS before 4.2.4 Build 20170313 contains an OS command injection flaw (CWE-78) that lets attackers gain administrator privileges and obtain sensitive information. The advisory describes the vectors only as unspecified, so the exact injection point is not documented in this record. With a network-reachable, unauthenticated attack path and full confidentiality, integrity and availability impact, this is a severe pre-auth flaw in a widely deployed NAS operating system.
Impact
An attacker can execute commands with administrative rights on the device and read sensitive data, effectively taking full control of the NAS and anything it stores or connects to.
Attack surface
The CVSS vector is AV:N/AC:L/PR:N/UI:N, meaning the flaw is reachable over the network with no authentication and no user interaction. The specific interface or parameter is not identified in the description.
Exploitation
CISA KEV does not list this CVE, but a public Exploit-DB entry (41842) exists and EPSS is 0.66146 (99.24th percentile), indicating high likelihood of exploitation activity. No ransomware group is documented as using it.
What to do
- Upgrade QNAP QTS to 4.2.4 Build 20170313 or later; this is the vendor-stated fixed build.
- If immediate upgrade is not possible, remove the device from direct internet exposure and restrict management access to trusted networks.
- Apply the vendor mitigation guidance referenced in the QNAP support advisory (con_show.php?cid=113).
- Change administrator credentials and audit accounts after any suspected exposure, since the flaw yields admin privileges.
- Monitor QNAP security advisories for follow-up fixes affecting the same QTS branch.
Detection
- Review QTS and system logs for unexpected command execution, new admin accounts, or configuration changes on NAS devices.
- Hunt for outbound connections or processes spawned by QTS web services that are not part of normal NAS behavior.
- Check for the fixed build version (4.2.4 Build 20170313) across the fleet and flag any device still below it.
- Correlate network access logs to QTS management interfaces from untrusted sources with signs of exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/97059 | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/97072 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038091 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/41842/ | |
| https://www.qnap.com/en-us/releasenotes/ | Release NotesVendor Advisory |
| https://www.qnap.com/en/support/con_show.php?cid=113 | MitigationVendor Advisory |
| http://www.securityfocus.com/bid/97059 | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/97072 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038091 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/41842/ | |
| https://www.qnap.com/en-us/releasenotes/ | Release NotesVendor Advisory |
| https://www.qnap.com/en/support/con_show.php?cid=113 | MitigationVendor Advisory |
Track CVE-2017-6360 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6360), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.