First published: Wed Dec 04 2019(Updated: )
This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | =4.2.6 | |
QNAP QTS | =4.3.3.0868 | |
QNAP QTS | =4.3.3.0998 | |
QNAP QTS | =4.3.4.0899 | |
QNAP QTS | =4.3.4.1029 | |
QNAP QTS | =4.3.6.0895 | |
QNAP QTS | =4.3.6.0907 | |
QNAP QTS | =4.3.6.0923 | |
QNAP QTS | =4.3.6.0944 | |
QNAP QTS | =4.3.6.0959 | |
QNAP QTS | =4.3.6.0979 | |
QNAP QTS | =4.3.6.0993 | |
QNAP QTS | =4.3.6.1013 | |
QNAP QTS | =4.3.6.1033 | |
QNAP QTS | =4.4.1.0948-beta | |
QNAP QTS | =4.4.1.0949-beta | |
QNAP QTS | =4.4.1.0978-beta_2 | |
QNAP QTS | =4.4.1.0998-beta_3 | |
QNAP QTS | =4.4.1.0999-beta_3 | |
QNAP QTS | =4.4.1.1031-beta_4 | |
QNAP QTS | =4.4.1.1033-beta_4 | |
QNAP QTS | =4.4.1.1064 | |
QNAP QTS | =4.4.1.1081 | |
QNAP QTS | =4.4.1.1086 | |
QNAP QTS | =4.4.1.1101 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0730 is classified as a critical command injection vulnerability allowing remote command execution.
To fix CVE-2018-0730, update your QNAP QTS to the latest available version as recommended by QNAP.
CVE-2018-0730 affects multiple versions including 4.2.6 and several iterations of 4.3.x and 4.4.x.
CVE-2018-0730 can be exploited by attackers with network access to an affected QNAP NAS device.
CVE-2018-0730 is associated with command injection attacks that can execute arbitrary commands on the device.