cbcvebase.
CVE-2021-28799
published 2021-05-13

CVE-2021-28799: An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote…

PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-21
Exploited in the wild
EPSS
78.25%
99.5th percentile
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .

Affected

8 ranges
VendorProductVersion rangeFixed in
qnaphybrid_backup_sync< 16.0.041516.0.0415
qnaphybrid_backup_sync< 3.0.2104123.0.210412
qnaphybrid_backup_sync< 3.0.2104113.0.210411
qnaphybrid_backup_sync< 16.0.041916.0.0419
qnap_systems_inchbs_3>= unspecified < v16.0.0415v16.0.0415
qnap_systems_inchbs_3>= unspecified < v3.0.210412v3.0.210412
qnap_systems_inchbs_3>= unspecified < v3.0.210411v3.0.210411
qnap_systems_inchbs_3>= unspecified < v16.0.0419v16.0.0419

Detection & IOCsextracted from sources · hover to see the quote

cookiejisoosocoolhbsmgnt
ip64.42.152.46
path/cgi-bin/backup/hbs_mgnt.cgi
command{"act":"run_cmd","sid":"jisoosocoolhbsmgnt","cmd":"cat /etc/passwd"}
  • Detect CVE-2021-28799 exploitation by matching POST requests to /cgi-bin/backup/hbs_mgnt.cgi containing the hard-coded session ID 'jisoosocoolhbsmgnt' in the JSON body
  • HTTP response matching for successful exploitation: JSON body containing all three of 'admin:.*:0:0:', '"cgi_log":', and '"result":' with Content-Type application/json and HTTP 200
  • Hunt for eCh0raix ransomware payload delivery from IP 64.42.152.46 targeting QNAP HBS3 via CVE-2021-28799
  • Identify new eCh0raix variant by GoLang compilation path rct_cryptor_universal in binary strings, distinguishing it from older qnap_crypt_worker samples
  • Use Shodan query 'product:"QNAP"' to identify internet-exposed QNAP NAS devices potentially vulnerable to CVE-2021-28799
  • ·The hard-coded session ID 'jisoosocoolhbsmgnt' is specific to the HBS 3 authentication bypass; it is embedded in the exploit payload and not a user-configurable value
  • ·The new eCh0raix variant uses a different C2 URL format (API key-based) compared to the previous variant (Campaign ID numbers); C2 is reached via a hard-coded SOCKS proxy over Tor
  • ·The syno flag in the new eCh0raix variant switches encryption target to hardcoded Synology volume paths (/volume[0-9]); without it, the 's' flag or default '/' is used for QNAP targets

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck10.0CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.