this post was submitted on 07 Feb 2025
45 points (100.0% liked)

Selfhosted

41903 readers
568 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

This may require a manual install, as the patching for this may not auto-run.

A vulnerability allows man-in-the-middle attackers to hijack the authentication of administrators.

The vulnerability reported by PWN2OWN 2024 (ZDI-CAN-25487) has been addressed.

top 7 comments
sorted by: hot top controversial new old
[–] deegeese@sopuli.xyz 11 points 6 hours ago (1 children)

What’s the exposure surface of this if I have remote access disabled?

[–] catloaf@lemm.ee 1 points 2 hours ago

Probably none. This is a MITM attack, so they need to be between you and the device. Usually that's done by being on the local network, though it could also be someone who has compromised your router/firewall appliance.

Of course, you should never expose services like this to the Internet. If you need remote access, use a VPN.

[–] Xanza@lemm.ee 5 points 5 hours ago

Update came through this morning. 7.2.2-72806 Update 3.

[–] Showroom7561@lemmy.ca 4 points 5 hours ago (1 children)

Just got the update. Good timing, because over the last week, I've had DOZENS upon DOZENS of IP addresses auto-blocked.

Before that, the last blocked IP address was like in September, so someone/something is probing.

[–] mipadaitu@lemmy.world 4 points 4 hours ago

I have a watt meter monitoring the power usage of my NAS. Out of all my checks, I assume that's how I'm going to know I get hacked before anything else.

[–] 0ndead@infosec.pub 1 points 6 hours ago (1 children)

Anybody know if this effects 6.2.4?

[–] non_burglar@lemmy.world 2 points 4 hours ago

According to this, 6.2.4.x is not affected.