This writeup details multiple vulnerabilities in Lian Li NAS devices, including hardcoded cookie authentication bypass, backdoored accounts, and privilege escalation via Telnet. It also lists accessible CGI endpoints and potential CSRF attack vectors.
Classification
Writeup 90%
Attack Type
Auth Bypass | Info Leak
Complexity
Trivial
Reliability
Reliable
Target:Lian Li NAS (firmware G5S604121826700)
No auth needed
Prerequisites:Network access to the NAS device · Ability to set cookies in the browser