QNAP released a security advisory detailing the critical PHP vulnerabilities that allow an attacker to Remote Code on QNAP NAS Devices.
According to the advisory, “A Vulnerability has been reported to affect PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24, and 7.3.x below 7.3.11 with improper nginx configuration. If exploited, the vulnerability allows attackers to gain remote code execution”.
The three-year-old flaw, tracked as (CVE-2019-11043), has a CVSS severity score of 9.8 and affects several PHP versions. For the vulnerability to be exploited, both Nginx and PHP-fpm must be running.
Only PHP installations with improper Nginx configurations are affected by this flaw. Moreover, both Nginx and PHP-fpm must be installed and running on the NAS device for the vulnerability to be leveraged.
The company noted that QTS, QuTS hero or QuTScloud does not have Nginx installed by default; QNAP NAS is not affected by this vulnerability in the default state.
The patched OS versions include:
QNAP inform the customers who cannot locate the ransom note after upgrading the firmware to enter the received DeadBolt decryption key to reach out to QNAP Support for assistance
On a regular basis, it is recommended to regularly update your system to the latest version to benefit from vulnerability fixes. Customers can check the product support status to observe the recent updates available for their NAS model.
QNAP customers who would like to update their NAS devices to the latest firmware automatically need to log on to QTS, QuTS hero, or QuTScloud as administrator and click the “Check for Update” button under Control Panel > System > Firmware Update.
The customers can also download the update from the QNAP website. Go to Support > Download Center and then perform a manual update for your specific device. Notably, this warning comes a week after QNAP revealed that it’s thoroughly investigating one more wave of ‘DeadBolt ransomware’ attacks targeting QNAP NAS devices running outdated versions of QTS 4.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.
Multinational engineering and technology services firm Tata Technologies has reportedly fallen victim to a significant…
U.S. authorities announced the seizure of $31 million tied to the 2021 Uranium Finance decentralized…
Imagine a government that tracks your daily movements, monitors your communications, and catalogs your digital…
A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt sensitive…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows privilege…
Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under limited,…