cbcvebase.
CVE-2024-50388
published 2024-12-06

CVE-2024-50388: An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to…

PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITW
Exploited in the wild
EPSS
2.31%
81.5th percentile
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later

Affected

2 ranges
VendorProductVersion rangeFixed in
qnaphybrid_backup_sync
qnap_systems_inchbs_3_hybrid_backup_sync>= 25.1.x < 25.1.1.67325.1.1.673

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is an OS command injection in HBS 3 Hybrid Backup Sync; detection should focus on unexpected OS command execution originating from the HBS 3 process on QNAP NAS devices (TS-464 and similar).
  • Exploitation allows remote attackers to execute arbitrary commands and gain admin privileges without authentication; monitor for privilege escalation to admin from non-admin sessions on QNAP QTS/QuTS hero.
  • The attack surface is remote and unauthenticated; monitor for anomalous inbound requests to HBS 3 Hybrid Backup Sync service endpoints on Internet-exposed QNAP NAS devices.
  • ·Only HBS 3 Hybrid Backup Sync versions in the 25.1.x line are confirmed vulnerable; the fix is version 25.1.1.673 and later. Ensure version checks target this specific branch.
  • ·Full technical exploitation details (e.g., specific vulnerable endpoint, payload structure) have not yet been published; Trend Micro ZDI has a 90-day disclosure window post-Pwn2Own before releasing full details.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.5CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.