CVE-2024-32764
A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fixed the vulnerability in the following version: myQNAPcloud Link 2.4.51 and later
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
- EPSS probability
- 0.42%
- CWE
- CWE-306, CWE-346, CWE-749
- Published
- 2024-04-26
- Last modified
- 2026-03-13
Affected products
- QNAP Systems Inc. myQNAPcloud Link
Weakness type
Related vulnerabilities
- CVE-2026-77974 — Softish C6 Ear Camera and EarVision Android Application Missing authentication for critical function
- CVE-2026-79961 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-11838 — Improper Authorization in Yordam Informatics' Library Reservation System
- CVE-2026-85981 — Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been...
- CVE-2026-86808 — moltis-org moltis vault.rs vault_recovery_handler missing authentication
- CVE-2026-73004 — Windows Autopilot Tampering Vulnerability
- CVE-2026-72964 — Windows Internet Connection Sharing (ICS) Tampering Vulnerability