First published: Fri Sep 14 2018(Updated: )
Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary commands in the compromised application.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Music Station | <=5.1.2 | |
QNAP QTS | =4.3.3 | |
QNAP QTS | =4.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0718 is a command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4.
CVE-2018-0718 has a severity level of critical with a CVSS score of 9.8.
CVE-2018-0718 affects Qnap Music Station version 5.1.2 and earlier, allowing remote attackers to run arbitrary commands in the compromised application.
No, QNAP QTS 4.3.3 is not vulnerable to CVE-2018-0718.
No, QNAP QTS 4.3.4 is not vulnerable to CVE-2018-0718.
To fix CVE-2018-0718, it is recommended to update Music Station to a version later than 5.1.2 and QNAP QTS to a version later than 4.3.4.