#VU54553 Missing Authentication for Critical Function in HBS 3 Hybrid Backup Sync - CVE-2021-28809
Published: July 5, 2021 / Updated: July 8, 2021
HBS 3 Hybrid Backup Sync
QNAP Systems, Inc.
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authentication in the within the RTSS server. A remote non-authenticated attacker can send a specially crafted request to port 8899/TCP and execute arbitrary code in the context of the Administrator.