CVE-2017-12582
CRITICALQNAP TS-212P Firmware 4.2.1 build 20160601 - Missing Authorization in Surveillance Station
Title source: llmDescription
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can access at Surveillance Station.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
http://www.kth.ninja/2017/08/qnap-surveillance-station.html
Scores
CVSS v3
9.8
EPSS
0.0034
EPSS Percentile
57.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-862
Status
published
Products (1)
qnap/ts-212p_firmware
4.2.1
Published
Aug 18, 2017
Tracked Since
Feb 18, 2026