CVE-2018-0718

CRITICAL

QNAP Music Station < 5.1.2 - Remote Command Injection

Title source: llm
STIX 2.1

Description

Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary commands in the compromised application.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0573
EPSS Percentile 90.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (1)
qnap/music_station < 5.1.2
Published Sep 14, 2018
Tracked Since Feb 18, 2026