QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign. Required action: Apply updates per vendor instructions.
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. Required action: Apply updates per vendor instructions.
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. Required action: Apply updates per vendor instructions.
QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system. Required action: Apply updates per vendor instructions.
QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system. Required action: Apply updates per vendor instructions.
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. Required action: Apply updates per vendor instructions.
A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. Required action: Apply updates per vendor instructions.
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. Required action: Apply updates per vendor instructions.
QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution. Required action: Apply updates per vendor instructions.
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. Required action: Apply updates per vendor instructions.