漏洞描述 QNAP Qsync Central是中国台湾威联通科技(QNAP)公司的一个 NAS 上基于云的文件同步服务。 QNAP Qsync Central 4.5.0.7版本之前版本存在信任管理问题漏洞,该漏洞源于证书验证不当,可能危及系统安全。
相关漏洞推荐 QNAP Qsync Central 路径遍历漏洞 QNAP Qsync Central 路径遍历漏洞 QNAP Qsync Central SQL注入漏洞 POC CVE-2018-15517: D-Link Central WifiManager - Server-Side Request Forgery POC CVE-2019-13372: D-Link Central WiFi Manager CWM(100) - Remote Code Execution POC CVE-2020-10189: ManageEngine Desktop Central Java Deserialization POC CVE-2020-9043: WordPress wpCentral <1.5.1 - Information Disclosure POC CVE-2021-44515: Zoho ManageEngine Desktop Central - Remote Code Execution POC CVE-2024-45241: CentralSquare CryWolf - Path Traversal POC dlink-centralized-default-login: D-Link AC Centralized Management System - Default Login POC ac-default-login: AC Centralized Management System - Default password POC manage-engine-dc-log4j-rce: Manage Engine Desktop Central - Remote Code Execution (Apache Log4j) Zoho ManageEngine Desktop Central 存在远程代码执行漏洞(CVE-2021-44515)