cbcvebase.
CVE-2023-41291
published 2024-04-26

CVE-2023-41291: A path traversal vulnerability has been reported to affect QuFirewall. If exploited, the vulnerability could allow authenticated administrators to read the…

PriorityP426medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.45%
36.2th percentile
A path traversal vulnerability has been reported to affect QuFirewall. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: QuFirewall 2.4.1 ( 2024/02/01 ) and later

Affected

2 ranges
VendorProductVersion rangeFixed in
qnapqufirewall< 2.4.12.4.1
qnap_systems_incqufirewall>= 2.4.x < 2.4.1 ( 2024/02/01 )2.4.1 ( 2024/02/01 )
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.