CVE-2017-12582

CRITICAL

QNAP TS-212P Firmware 4.2.1 build 20160601 - Missing Authorization in Surveillance Station

Title source: llm
STIX 2.1

Description

Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can access at Surveillance Station.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
http://www.kth.ninja/2017/08/qnap-surveillance-station.html

Scores

CVSS v3 9.8
EPSS 0.0034
EPSS Percentile 57.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (1)
qnap/ts-212p_firmware 4.2.1
Published Aug 18, 2017
Tracked Since Feb 18, 2026