Vulnerability record · CVE-2021-28799 · published 13 May 2021
CVE-2021-28799: QNAP HBS 3 improper authorization allows remote login
Qnap · Hybrid Backup Sync
QNAP Hybrid Backup Sync 3 (HBS 3) contains an improper authorization flaw that lets remote attackers log in to the NAS device. The issue affects multiple HBS 3 builds across QTS 4.5.2, QTS 4.3.6, QTS 4.3.4, QTS 4.3.3, QuTS hero h4.5.1 and QuTScloud c4.5.1~c4.5.4, while HBS 2 and HBS 1.3 are not affected. Because the flaw bypasses authorization on a network-exposed service, it is a serious risk to internet-facing QNAP devices.
Description
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing with known ransomware use, and a 0.7825 EPSS probability make this an actively exploited, remotely reachable authorization bypass.
What it is
QNAP Hybrid Backup Sync 3 (HBS 3) contains an improper authorization flaw that lets remote attackers log in to the NAS device. The issue affects multiple HBS 3 builds across QTS 4.5.2, QTS 4.3.6, QTS 4.3.4, QTS 4.3.3, QuTS hero h4.5.1 and QuTScloud c4.5.1~c4.5.4, while HBS 2 and HBS 1.3 are not affected. Because the flaw bypasses authorization on a network-exposed service, it is a serious risk to internet-facing QNAP devices.
Impact
An attacker gains the ability to log in to the affected device without valid credentials, which can lead to full control of the NAS and its data. CISA's KEV entry notes known ransomware campaign use tied to this vulnerability.
Attack surface
The CVSS vector is network-reachable with no privileges and no user interaction required, so the flaw is exploitable directly over the network against the HBS 3 service. No authentication is needed to reach the vulnerable code path.
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-03-31 with a due date of 2022-04-21 and flags known ransomware campaign use. EPSS gives a 30-day exploitation probability of 0.7825 (99.554th percentile), indicating very high likelihood of active exploitation.
What to do
- Update HBS 3 to the fixed build for your platform: v16.0.0415 or later on QTS 4.5.2, v3.0.210412 or later on QTS 4.3.6, v3.0.210411 or later on QTS 4.3.4 and 4.3.3, v16.0.0419 or later on QuTS hero h4.5.1 and QuTScloud c4.5.1~c4.5.4.
- If immediate patching is not possible, remove HBS 3 from internet exposure and restrict access to trusted management networks.
- Disable or block external access to the HBS 3 service and any related management ports until the update is applied.
- Review QNAP accounts and access logs for unexpected logins or new administrative sessions.
- Apply the vendor advisory QSA-21-13 guidance and verify the installed HBS 3 version after updating.
Detection
- Monitor QNAP authentication and access logs for successful logins from unexpected source IPs or at unusual times.
- Alert on HBS 3 service connections from external or untrusted networks.
- Hunt for new or modified administrator accounts and unexpected configuration changes on QNAP NAS devices.
- Correlate NAS log events with known ransomware indicators and outbound connections from the device.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-28799 to the Known Exploited Vulnerabilities catalog on 31 March 2022 as "QNAP NAS Improper Authorization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 21 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.qnap.com/en/security-advisory/QSA-21-13 | Vendor Advisory |
| https://www.qnap.com/en/security-advisory/QSA-21-13 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-28799 | US Government Resource |
Track CVE-2021-28799 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-28799), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.