The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7...
Moderate severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Feb 15, 2024
Description
Published by the National Vulnerability Database
Sep 21, 2009
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Feb 15, 2024
The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a brute-force attack.
References