Showing 4 vulnerabilities on this page for QNAP Media Streaming Add-On

Signals CISA KEV Ransomware Nuclei
QNAP vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.

CWE-78Mar 8, 2018
CVSS9.8v3.0EPSS2.33%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.

CWE-352Mar 8, 2018
CVSS8.8v3.0EPSS0.46%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted link, not the normal page.

CWE-79Mar 8, 2018
CVSS6.1v3.0EPSS0.772%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.

CWE-287Mar 8, 2018
CVSS6.5v3.0EPSS0.683%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX