CVE-2023-45038
Music Station
Record summary
CVE-2023-45038 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.
Description
An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Music Station 5.4.0 and later
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 16, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 6, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
music_stationBrowse QNAP / music_station | VulnCheck | Version data not supplied | |
Music StationBrowse QNAP Systems Inc. / Music StationDefault status: unaffected | CVE List | 5.4.x to < 5.4.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMQNAP Music Station < 5.4.0 - Authentication BypassCVSS 4.3
An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Music Station 5.4.0 and later
Impact
Unauthenticated attackers can bypass authentication in Music Station to read arbitrary files from the QNAP system including /etc/passwd, potentially accessing sensitive configuration files and user credentials.
Remediation
Update QNAP Music Station to version 5.4.0 or later that implements proper authentication validation in the as_get_file_api.php endpoint.
Source: ProjectDiscovery