We were absolutely sure all of our bugs would dupe, because we were the 7th SOHO smash-up and many others had the same 2 targets. But they’re all unique! 🥳
I would be quite worried if I had a QNAP router. 🙃 #Pwn2Own
Confirmed! In the penultimate attempt of Day 2, @daankeuper, @xnyhps, and @notkmhn from @sector7_nl combined 4 bugs, including a command injection and a path traversal to going from the QNAP QHora-322 to the TrueNAS Mini X. They earn $25,000 and 10 Master of Pwn points. #Pwn2Own
We had a short look at the buffer overflow found by fuzzing `process_browse_data` to determine its exploitability. Conclusion: this bug alone won't give you RCE, or even an info leak.
Hiding the fact your OS has multiple RCE vulnerabilities (that will not be fixed) behind a login, in a PDF that’s mostly non-disclosure legalese is pretty irresponsible, if you ask me. 🤬
If you have any devices that use SiLabs’ Gecko OS you might want to replace them.
We have published the 2nd writeup about the EV vulnerabilities we exploited for #Pwn2Own Automotive: the JuiceBox 40.
Despite what the @thezdi advisories say, these bugs were NOT fixed by the vendor! SiLabs has declared the product EOL and won't fix it.
sector7.computest.nl/post/2024-08-p…