ZDI-CAN-12048: QNAP NAS MusicStation Directory Traversal Arbitrary File Creation Vulnerability
This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of QNAP NAS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MusicStation application. When parsing the arttype request parameter, the process does not properly validate a user-supplied path prior to using it in file operations.An attacker can leverage this vulnerability to create files in the context of the admin user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-12048?
The severity of ZDI-CAN-12048 is considered high due to the ability for unauthorized attackers to create arbitrary files.
How do I fix ZDI-CAN-12048?
To fix ZDI-CAN-12048, you should update your QNAP NAS to the latest version provided by QNAP that addresses this vulnerability.
What software is affected by ZDI-CAN-12048?
ZDI-CAN-12048 affects the MusicStation application on QNAP NAS installations.
Is authentication required to exploit ZDI-CAN-12048?
No, authentication is not required to exploit ZDI-CAN-12048.
Who can exploit ZDI-CAN-12048?
Network-adjacent attackers can exploit ZDI-CAN-12048.