Exploitation Summary
CVE-2017-6360 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Harry Sintonen.
AI-analyzed exploit summary The exploit demonstrates unauthenticated and authenticated remote command execution (RCE) vulnerabilities in QNAP QTS firmware via command injection in CGI binaries. It includes detailed examples of crafted HTTP requests to execute arbitrary commands as root.
Description
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
Exploits (1)
The exploit demonstrates unauthenticated and authenticated remote command execution (RCE) vulnerabilities in QNAP QTS firmware via command injection in CGI binaries. It includes detailed examples of crafted HTTP requests to execute arbitrary commands as root.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H