First published: Mon Nov 02 2020(Updated: )
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Music Station | >=5.3.0<5.3.11 | |
QNAP QTS | =4.4.3 | |
Qnap Music Station | <5.1.13 | |
QNAP QTS | =4.3.4 | |
Qnap Music Station | >=5.2.0<5.2.9 | |
QNAP QTS | =4.3.6 | |
QNAP QTS | =4.3.3 |
QNAP have already fixed the issue in the following Music Station: QTS 4.3.3: Music Station 5.1.13 and later QTS 4.3.4: Music Station 5.1.13 and later QTS 4.3.6: Music Station 5.2.9 and later QTS 4.4.3: Music Station 5.3.11 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19950 is a command injection vulnerability that could allow remote attackers to execute arbitrary commands.
Music Station versions prior to 5.1.13, versions prior to 5.2.9, and versions prior to 5.3.11 are affected by CVE-2018-19950.
CVE-2018-19950 has a severity value of 9.8 (critical).
To fix CVE-2018-19950, users should update Music Station to version 5.1.13, 5.2.9, or 5.3.11.
You can find more information about CVE-2018-19950 in the QNAP security advisory QSA-20-10.