CVE-2018-0710
HIGHQnap Q'center < 1.7.1063 - OS Command Injection
Title source: ruleDescription
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Core Security · textwebappshardware
https://www.exploit-db.com/exploits/45015
References (6)
Scores
CVSS v3
8.8
EPSS
0.1916
EPSS Percentile
95.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-78
Status
published
Affected Products (1)
qnap/q\'center
< 1.7.1063
Timeline
Published
Jul 17, 2018
Tracked Since
Feb 18, 2026