CVE-2021-28799
published 2021-05-13CVE-2021-28799: An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-21
Exploited in the wild
EPSS
78.25%
99.5th percentile
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| qnap | hybrid_backup_sync | < 16.0.0415 | 16.0.0415 |
| qnap | hybrid_backup_sync | < 3.0.210412 | 3.0.210412 |
| qnap | hybrid_backup_sync | < 3.0.210411 | 3.0.210411 |
| qnap | hybrid_backup_sync | < 16.0.0419 | 16.0.0419 |
| qnap_systems_inc | hbs_3 | >= unspecified < v16.0.0415 | v16.0.0415 |
| qnap_systems_inc | hbs_3 | >= unspecified < v3.0.210412 | v3.0.210412 |
| qnap_systems_inc | hbs_3 | >= unspecified < v3.0.210411 | v3.0.210411 |
| qnap_systems_inc | hbs_3 | >= unspecified < v16.0.0419 | v16.0.0419 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect CVE-2021-28799 exploitation by matching POST requests to /cgi-bin/backup/hbs_mgnt.cgi containing the hard-coded session ID 'jisoosocoolhbsmgnt' in the JSON body ↗
- →HTTP response matching for successful exploitation: JSON body containing all three of 'admin:.*:0:0:', '"cgi_log":', and '"result":' with Content-Type application/json and HTTP 200 ↗
- →Hunt for eCh0raix ransomware payload delivery from IP 64.42.152.46 targeting QNAP HBS3 via CVE-2021-28799 ↗
- →Identify new eCh0raix variant by GoLang compilation path rct_cryptor_universal in binary strings, distinguishing it from older qnap_crypt_worker samples ↗
- →Use Shodan query 'product:"QNAP"' to identify internet-exposed QNAP NAS devices potentially vulnerable to CVE-2021-28799 ↗
- ·The hard-coded session ID 'jisoosocoolhbsmgnt' is specific to the HBS 3 authentication bypass; it is embedded in the exploit payload and not a user-configurable value ↗
- ·The new eCh0raix variant uses a different C2 URL format (API key-based) compared to the previous variant (Campaign ID numbers); C2 is reached via a hard-coded SOCKS proxy over Tor ↗
- ·The syno flag in the new eCh0raix variant switches encryption target to hardcoded Synology volume paths (/volume[0-9]); without it, the 's' flag or default '/' is used for QNAP targets ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck10.0CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
QNAP NAS Improper Authorization Vulnerability
cisa·2022-03-31·CVSS 9.8
CVE-2021-28799 [CRITICAL] CWE-285 QNAP NAS Improper Authorization Vulnerability
Vulnerability: QNAP NAS Improper Authorization Vulnerability
Affected: QNAP Network Attached Storage (NAS)
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-28799
Remediation Due Date: 2022-04-21
GHSA
GHSA-4v9x-j7pr-8wxq: An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync
ghsa_unreviewed·2022-05-24
CVE-2021-28799 [CRITICAL] CWE-285 GHSA-4v9x-j7pr-8wxq: An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .
VulnCheck
QNAP NAS Improper Authorization Vulnerability
vulncheck·2021·CVSS 10.0
CVE-2021-28799 [CRITICAL] CWE-285 QNAP NAS Improper Authorization Vulnerability
QNAP NAS Improper Authorization Vulnerability
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
Affected: QNAP QNAP Network-Attached Storage (NAS)
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.qnap.com/en-us/security-advisory/QSA-21-15; https://www.qnap.com/en/security-advisory/qsa-21-12; https://www.secureblink.com/threat-research/qlocker-ransomware; https://threatpost.com/ech0raix-ransomware-variant-qnap-synology-nas-devices/168516/; https://unit42.paloaltonetworks.com/ech0raix-ransomware-soho/; https://cybersecurityworks.com/howdymanage/uploads/file/ransomware_index-update-q221-csw.pdf; https://cybersecurityworks.com/howdy
No detection rules found.
Nuclei
QNAP HBS 3 - Broken Access Control
nuclei·CVSS 9.8
CVE-2021-28799 [CRITICAL] QNAP HBS 3 - Broken Access Control
QNAP HBS 3 - Broken Access Control
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .
Template:
id: CVE-2021-28799
info:
name: QNAP HBS 3 - Broken Access Control
author: daffainfo
severity: critical
description: |
An improper authorization vulner
Bleepingcomputer
QNAP fixes NAS backup software zero-day exploited at Pwn2Own
blogs_bleepingcomputer·2024-10-29·CVSS 9.8
CVE-2024-50388 [CRITICAL] QNAP fixes NAS backup software zero-day exploited at Pwn2Own
## QNAP fixes NAS backup software zero-day exploited at Pwn2Own
## Sergiu Gatlan
QNAP has fixed a critical zero-day vulnerability exploited by security researchers on Thursday to hack a TS-464 NAS device during the Pwn2Own Ireland 2024 competition.
Tracked as CVE-2024-50388, the security flaw is caused by an OS command injection weakness in HBS 3 Hybrid Backup Sync version 25.1.x, the company's disaster recovery and data backup solution.
"An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands," QNAP said in a Tuesday security advisory.
The company has addressed the security bug in HBS 3 Hybrid Backup Sync 25.1.1.673 and later.
To update HBS 3 on your NAS dev
Unit42
SockDetour – a Silent, Fileless, Socketless Backdoor – Targets U.S. Defense Contractors
blogs_unit42·2022-02-24·CVSS 10.0
CVE-2021-28799 [CRITICAL] SockDetour – a Silent, Fileless, Socketless Backdoor – Targets U.S. Defense Contractors
Threat Research Center
Threat Research
Malware
## SockDetour – a Silent, Fileless, Socketless Backdoor – Targets U.S. Defense Contractors
Unit 42
Published: February 24, 2022
Malware
Threat Research
Vulnerabilities
Advanced Persistent Threat
Backdoor
CVE-2021-28799
CVE-2021-40539
CVE-2021-44077
TiltedTemple
Windows
## Executive Summary
Unit 42 has been tracking an APT campaign we name TiltedTemple, which we first identified in connection with its use of the Zoho ManageEngine ADSelfService Plus vulnerability CVE-2021-40539 and ServiceDesk Plus vulnerability CVE-2021-44077. The threat actors involved use a variety of techniques to gain access to and persistence in compromised systems and have successfully compromised more than a dozen organizations across the technology,
Unit42
SockDetour – a Silent, Fileless, Socketless Backdoor – Targets U.S. Defense Contractors
blogs_unit42·2022-02-24·CVSS 9.8
CVE-2021-40539 [CRITICAL] SockDetour – a Silent, Fileless, Socketless Backdoor – Targets U.S. Defense Contractors
## Executive Summary
Unit 42 has been tracking an APT campaign we name TiltedTemple, which we first identified in connection with its use of the Zoho ManageEngine ADSelfService Plus vulnerability CVE-2021-40539 and ServiceDesk Plus vulnerability CVE-2021-44077. The threat actors involved use a variety of techniques to gain access to and persistence in compromised systems and have successfully compromised more than a dozen organizations across the technology, energy, healthcare, education, finance and defense industries. In conducting further analysis of this campaign, we identified another sophisticated tool being used to maintain persistence, which we call SockDetour.
A custom backdoor, SockDetour is designed to serve as a backup backdoor in case the primary one is removed. It is diffic
Unit42
New eCh0raix Ransomware Variant Targets QNAP and Synology Network-Attached Storage Devices
blogs_unit42·2021-08-10·CVSS 10.0
CVE-2021-28799 [CRITICAL] New eCh0raix Ransomware Variant Targets QNAP and Synology Network-Attached Storage Devices
Threat Research Center
Threat Research
Ransomware
## New eCh0raix Ransomware Variant Targets QNAP and Synology Network-Attached Storage Devices
Ruchna Nigam
Haozhe Zhang
Zhibin Zhang
Published: August 10, 2021
Ransomware
Threat Research
Vulnerabilities
CVE-2021-28799
ECh0raix
IoT
NAS
QNAPCrypt
SOHO
## Executive Summary
Unit 42 researchers have discovered a new variant of eCh0raix ransomware targeting Synology network-attached storage (NAS) and Quality Network Appliance Provider (QNAP) NAS devices. To achieve this, attackers are also leveraging CVE-2021-28799 to deliver the new eCh0raix ransomware variant to QNAP devices. While eCh0raix is known ransomware that has historically targeted QNAP and Synology NAS devices in separate campaigns, this new variant is the first
Unit42
New eCh0raix Ransomware Variant Targets QNAP and Synology Network-Attached Storage Devices
blogs_unit42·2021-08-10·CVSS 10.0
CVE-2021-28799 [CRITICAL] New eCh0raix Ransomware Variant Targets QNAP and Synology Network-Attached Storage Devices
## Executive Summary
Unit 42 researchers have discovered a new variant of eCh0raix ransomware targeting Synology network-attached storage (NAS) and Quality Network Appliance Provider (QNAP) NAS devices. To achieve this, attackers are also leveraging CVE-2021-28799 to deliver the new eCh0raix ransomware variant to QNAP devices. While eCh0raix is known ransomware that has historically targeted QNAP and Synology NAS devices in separate campaigns, this new variant is the first time we’ve seen it combining functionality to target both QNAP and Synology NAS devices, demonstrating that some ransomware developers are continuing to invest in optimizing the tools used to target devices common in the small office and home office (SOHO).
We’re regularly seeing attacks with the eCh0raix ransomware va
Checkpoint
24th May – Threat Intelligence Report
blogs_checkpoint·2021-05-24
CVE-2021-21551 24th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 24th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th May, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has discovered multiple misconfiguration flaws in third party cloud services of Android applications, which have led to the exposure of sensitive personal data of more than 100 million Android users and developers. Many flaws were the result of improper configuration of real-time databases.
Check Point Harmo
Greynoiseio
Malicious Tag Roundup (May 24-Jun 4, 2021)
blogs_greynoiseio·CVSS 9.8
[CRITICAL] Malicious Tag Roundup (May 24-Jun 4, 2021)
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
Malicious Tag Roundup (May 10-21, 2021)
blogs_greynoiseio·CVSS 7.7
[HIGH] Malicious Tag Roundup (May 10-21, 2021)
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2021-05-13
Published
2022-03-31
Added to CISA KEV
Exploited in the wild