CVE-2018-14746: Command Injection
Published Nov 28, 2018
·Updated
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to run arbitrary commands on the NAS.
Affected Software
4 affected components
QNAP QTS=4.2.6
QNAP QTS=4.3.3
QNAP QTS=4.3.4
QNAP QTS=4.3.5
Event History
Nov 28, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-14746?
CVE-2018-14746 is considered a high severity vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2018-14746?
To mitigate CVE-2018-14746, upgrade your QTS software to version 4.3.6 or later where the vulnerability is patched.
3
Which versions of QTS are affected by CVE-2018-14746?
CVE-2018-14746 affects QTS versions 4.2.6, 4.3.3, 4.3.4, and 4.3.5.
4
What type of vulnerability is CVE-2018-14746?
CVE-2018-14746 is classified as a command injection vulnerability.
5
Can CVE-2018-14746 be exploited remotely?
Yes, CVE-2018-14746 can be exploited by remote attackers to execute arbitrary commands.