CVE-2018-0709

HIGH

QNAP Q'center < 1.7.1063 - Authenticated OS Command Injection via Date Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-0709. PoCs published by Core Security.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in QNAP Qcenter Virtual Appliance, including privilege escalation via API endpoint exposure of admin credentials and command injection in password change and network configuration functionalities.

Description

Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Core Security · textwebappshardware
https://www.exploit-db.com/exploits/45015

The exploit demonstrates multiple vulnerabilities in QNAP Qcenter Virtual Appliance, including privilege escalation via API endpoint exposure of admin credentials and command injection in password change and network configuration functionalities.

Classification
Working Poc 100%
Attack Type
Rce | Lpe | Info Leak
Complexity
Moderate
Reliability
Reliable
Target: QNAP Qcenter Virtual Appliance Version 1.6.1056 (20170825), 1.6.1075 (20171123)
Auth required
Prerequisites: Authenticated access to the Qcenter web console · Base64 encoding for password fields
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45015/
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Jul/45
Exploit, Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
https://www.securityfocus.com/archive/1/542141/100/0/threaded

Scores

CVSS v3 8.8
EPSS 0.1362
EPSS Percentile 96.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
qnap/q\'center < 1.7.1063
Published Jul 17, 2018
Tracked Since Feb 18, 2026