CVE-2018-0706

HIGH

QNAP Q'center Virtual Appliance <1.7.1063 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2018-0706. PoCs published by Metasploit, Core Security, Ivan Huertas, bcoles, including Metasploit module exploits/linux/http/qnap_qcenter_change_passwd_exec.

AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability (CVE-2018-0707) in QNAP Q'Center's `change_passwd` API, allowing authenticated users to execute arbitrary commands as the 'admin' OS user. It also leverages a separate password disclosure issue (CVE-2018-0706) to escalate privileges if non-admin credentials are provided.

Description

Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access sensitive information.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/45043

This Metasploit module exploits a command injection vulnerability (CVE-2018-0707) in QNAP Q'Center's `change_passwd` API, allowing authenticated users to execute arbitrary commands as the 'admin' OS user. It also leverages a separate password disclosure issue (CVE-2018-0706) to escalate privileges if non-admin credentials are provided.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: QNAP Q'Center virtual appliance versions prior to 1.7.1083
Auth required
Prerequisites: Network access to the Q'Center web interface (port 443) · Valid credentials for any user (or admin credentials directly) · Target running a vulnerable version of Q'Center
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Core Security · textwebappshardware
https://www.exploit-db.com/exploits/45015

The exploit demonstrates multiple vulnerabilities in QNAP Qcenter Virtual Appliance, including privilege escalation via API endpoint exposure of admin credentials and command injection in password change and network configuration functionalities.

Classification
Working Poc 100%
Attack Type
Rce | Lpe | Info Leak
Complexity
Moderate
Reliability
Reliable
Target: QNAP Qcenter Virtual Appliance Version 1.6.1056 (20170825), 1.6.1075 (20171123)
Auth required
Prerequisites: Authenticated access to the Qcenter web console · Base64 encoding for password fields
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Ivan Huertas, bcoles · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/qnap_qcenter_change_passwd_exec.rb

This Metasploit module exploits a command injection vulnerability in QNAP Q'Center's `change_passwd` API, allowing authenticated users to execute arbitrary commands as the 'admin' user. It also leverages a separate password disclosure issue to escalate privileges if non-admin credentials are provided.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: QNAP Q'Center virtual appliance versions prior to 1.7.1083
Auth required
Prerequisites: Valid credentials for the 'admin' user account or any authenticated user to exploit the password disclosure issue
devstral-2 · analyzed Apr 23, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45015/
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Jul/45
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45043/
Exploit, Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
https://www.securityfocus.com/archive/1/542141/100/0/threaded

Scores

CVSS v3 8.8
EPSS 0.6070
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
qnap/q\'center < 1.7.1063
Published Jul 17, 2018
Tracked Since Feb 18, 2026