CVE-2018-0730

This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:qnap:qts:4.2.6:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.3.0868:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.3.0998:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.4.0899:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.4.1029:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.6.0895:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.6.0907:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.6.0923:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.6.0944:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.6.0959:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.6.0979:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.6.0993:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.6.1013:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.6.1033:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.4.1.0948:beta:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.4.1.0949:beta:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.4.1.0978:beta_2:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.4.1.0998:beta_3:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.4.1.0999:beta_3:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.4.1.1031:beta_4:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.4.1.1033:beta_4:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.4.1.1064:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.4.1.1081:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.4.1.1086:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.4.1.1101:*:*:*:*:*:*:*

History

21 Nov 2024, 03:38

Type Values Removed Values Added
References () https://www.qnap.com/zh-tw/security-advisory/nas-201911-20 - Vendor Advisory () https://www.qnap.com/zh-tw/security-advisory/nas-201911-20 - Vendor Advisory

Information

Published : 2019-12-04 17:16

Updated : 2024-11-21 03:38


NVD link : CVE-2018-0730

Mitre link : CVE-2018-0730

CVE.ORG link : CVE-2018-0730


JSON object : View

Products Affected

qnap

  • qts
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')