QID 730930
Date Published: 2023-10-31
QID 730930: QNAP Command Injection in QTS and in Media Streaming Add-On
QTS (QNAP Turbo NAS System) is a Turbo NAS Operating System, providing file storage, backup, disaster recovery, security management and virtualization applications for businesses; multimedia applications.
CVE-2017-10700: In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application..
Affected versions:
prior to QTS 4.2.6 build 20170905
prior to QTS 4.3.3.0262 build 20170727
QID Detection Logic:
This unauthenticated detection detects vulnerable versions depending on the version disclosed by making a call to the authLogin.cgi webpage.
Note: detection is practice as unable to check for media streaming add on
Successful exploitation of this vulnerability may allows arbitrary code execution
- nas-201709-11 -
www.qnap.com/en/security-advisory/nas-201709-11
CVEs related to QID 730930
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| nas-201709-11 |
|