A command injection vulnerability in QNAP QTS and QuTS hero that, when exploited, allows an attacker to execute arbitrary commands within the context of a compromised application. QNAP reports the issue is fixed in: QTS 4.5.2.1566 build 20210202 and later; QTS 4.5.1.1495 build 20201123 and later; QTS 4.3.6.1620 build 20210322 and later; QTS 4.3.4.1632 build 20210324 and later; QTS 4.3.3.1624 build 20210416 and later; QTS 4.2.6 build 20210327 and later; and QuTS hero h4.5.1.1491 build 20201119 and later.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python exploit (overkill.py) targeting a patched remote code execution vulnerability in QNAP QTS devices. The exploit abuses the QNAP device's mechanism for downloading XML files from update.qnap.com via insecure HTTP. By redirecting update.qnap.com to an attacker-controlled server (e.g., via DNS hijacking), the attacker can serve a malicious XML file containing a payload that is executed via a system call on the QNAP device, resulting in a reverse shell. The exploit script sets up a netcat listener for the shell and an HTTP server to deliver the payload. The repository consists of a single exploit script, a README with usage instructions and background, a license, and a .gitignore. The exploit is operational and requires the attacker to perform a man-in-the-middle attack to redirect the victim's traffic. No CVE is directly referenced, but the vulnerability is likely related to QNAP QTS versions patched in late 2020 and early 2021.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.