CVE-2021-28799

CRITICAL(10.0)KEVRansomwareLikely Exploited

QNAP NAS Improper Authorization Vulnerability

Description

CVE-2021-28799 is an improper authorization vulnerability in QNAP NAS devices that allows unauthorized remote attackers to gain access to the system. The vulnerability involves a backdoor-like mechanism that can be exploited to bypass normal authentication controls. It was added to CISA's Known Exploited Vulnerabilities (KEV) catalog with confirmed ransomware associations. With an EPSS score of 4.9% (93.5th percentile), this vulnerability has been actively leveraged in ransomware campaigns against NAS devices.

KEV Information

Vendor
QNAP
Product
Network Attached Storage (NAS)
Date Added
March 31, 2022
Due Date
April 21, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0

CWEs

Affected Products

VendorProductVersion
qnaphybrid backup sync< 16.0.0415; < 3.0.210412; < 3.0.210411; < 16.0.0419

Multiple CVSS Assessments

Source: [email protected](Secondary)
10.0
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-284: Improper Access Control

Improper access control occurs when an application does not properly restrict access to resources, allowing unauthorized users to perform actions they should not be able to. In CVE-2021-28799, QNAP NAS devices contain an improper authorization mechanism that allows remote attackers to bypass access controls and gain unauthorized system access. For more details, see CWE-284.

Impact Analysis

Exploitation of this vulnerability provides unauthorized access to QNAP NAS devices, which typically store critical organizational data including file shares, backups, and sensitive documents. The confirmed ransomware association makes this vulnerability particularly dangerous, as attackers have used it to encrypt data stored on NAS devices and demand ransom payments. Since NAS devices frequently serve as backup targets, ransomware deployed through this vulnerability can eliminate an organization's recovery options, making it more likely that victims will pay the ransom. The unauthorized access also enables data theft, persistent backdoor installation, and use of the compromised NAS as a pivot point for further network attacks.

Exploit Maturity

CVE-2021-28799 was added to CISA's KEV catalog on March 31, 2022, with confirmed ransomware association (Known). The EPSS score of 4.9% (93.5th percentile) reflects active exploitation activity. The vulnerability was notably exploited by the Qlocker ransomware campaign, which targeted QNAP NAS devices worldwide, encrypting user data into 7-zip archives and demanding Bitcoin ransom payments. The campaign affected thousands of QNAP NAS devices and demonstrated the high-value nature of NAS-targeted attacks.

Remediation

  1. Update QNAP HBS 3 (Hybrid Backup Sync) to the latest version and update the QTS or QuTS hero firmware, as required by CISA's KEV catalog.
  2. Remove any unauthorized user accounts, particularly accounts created through exploitation that may serve as persistent backdoors.
  3. Disable remote access to the NAS until the vulnerability is patched, particularly disabling port forwarding and UPnP on the router.
  4. Review all data on the NAS for signs of encryption or unauthorized modification that could indicate past exploitation.
  5. Implement the 3-2-1 backup strategy with at least one offline backup copy to protect against ransomware targeting NAS devices.

Technical Details

The vulnerability exists in the authorization mechanism of QNAP NAS firmware, where an improper access control flaw allows remote attackers to bypass the normal authentication process. The flaw is related to hard-coded or inadequately protected credentials in certain QNAP services that can be exploited to gain system-level access without providing valid user credentials. Once access is obtained, the attacker has the permissions necessary to read, modify, and encrypt all data on the NAS. The Qlocker ransomware campaign exploited this vulnerability by using the backdoor access to run 7-zip commands that encrypted user data into password-protected archives, then deleted the original files.

Frequently Asked Questions

What is CVE-2021-28799?

CVE-2021-28799 is an improper authorization vulnerability in QNAP NAS devices that allows remote attackers to gain unauthorized access to the system by bypassing normal authentication controls. It has been exploited in ransomware campaigns targeting NAS devices.

Was this used in the Qlocker ransomware attacks?

Yes, CVE-2021-28799 was exploited by the Qlocker ransomware campaign that targeted QNAP NAS devices worldwide. Attackers used the vulnerability to gain access and then encrypted user files into password-protected 7-zip archives, demanding Bitcoin ransom payments for the decryption password.

How can I check if my NAS has been compromised?

Look for unexpected 7-zip archives containing your files, unauthorized user accounts on the NAS, unfamiliar running processes, and ransom notes in your file directories. Also check the NAS system logs for unauthorized login attempts or unusual activity.

Should I pay the ransom if my data is encrypted?

Law enforcement agencies generally advise against paying ransom as it funds criminal operations and does not guarantee data recovery. Instead, focus on restoring from backups if available. For the Qlocker campaign specifically, there were reports of victims not receiving decryption keys even after payment.

CVSS Score

10.0
CRITICAL(10.0)

EPSS Score

EPSS Score78.25%
EPSS Percentile99.5%

Dates

PublishedMay 13, 2021
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.