cbcvebase.
CVE-2017-7637
published 2018-06-05

CVE-2017-7637: QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges.

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges.

Affected

1 ranges
VendorProductVersion rangeFixed in
qnapnas_proxy_server< 1.3.01.3.0

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
CVE-2017-7637 — OS Command Injection in Qnap | cvebase