Record summary

CVE-2023-45038 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.

Description

An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Music Station 5.4.0 and later

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 16, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 6, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unaffected

CVE List5.4.x to < 5.4.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMQNAP Music Station < 5.4.0 - Authentication BypassCVSS 4.3

An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Music Station 5.4.0 and later

Impact

Unauthenticated attackers can bypass authentication in Music Station to read arbitrary files from the QNAP system including /etc/passwd, potentially accessing sensitive configuration files and user credentials.

Remediation

Update QNAP Music Station to version 5.4.0 or later that implements proper authentication validation in the as_get_file_api.php endpoint.

WeaknessesCWE-287
Authorsdaffainfo
Template tagscvecve2023qnapmusic_stationauth-bypassvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:qnap:music_station:*:*:*:*:*:*:*:*
Shodan: http.title:"qnap"
FOFA: title="qnap"
Google: intitle:"qnap"

Source: ProjectDiscovery

References

2