CVE-2022-23765: Iptime NAS1DUAL Firmware

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the root through a POST request.

Affected products

  • Iptime NAS1DUAL Firmware: before 1.4.86 (fixed in 1.4.86)
  • Iptime NAS2DUAL Firmware: before 1.4.86 (fixed in 1.4.86)
  • Iptime NAS4DUAL Firmware: before 1.4.86 (fixed in 1.4.86)

Published 2022-08-17. Last modified 2026-06-17.