Qnap Media Streaming Add-On vulnerabilities
4 known vulnerabilities affecting qnap/qnap_media_streaming_add-on.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2017-7640CRITICALCVSS 9.8v421.1.0.2, 430.1.2.0, and earlier2018-03-08
CVE-2017-7640 [CRITICAL] CWE-78 CVE-2017-7640: QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
cvelistv5nvd
CVE-2017-7641HIGHCVSS 8.8v421.1.0.2, 430.1.2.0, and earlier2018-03-08
CVE-2017-7641 [HIGH] CWE-352 CVE-2017-7641: QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utili
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.
cvelistv5nvd
CVE-2017-7638MEDIUMCVSS 6.5v421.1.0.2, 430.1.2.0, and earlier2018-03-08
CVE-2017-7638 [MEDIUM] CWE-287 CVE-2017-7638: QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authe
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.
cvelistv5nvd
CVE-2017-7634MEDIUMCVSS 6.1v421.1.0.2, 430.1.2.0, and earlier2018-03-08
CVE-2017-7634 [MEDIUM] CWE-79 CVE-2017-7634: Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.
Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted link, not the normal page.
cvelistv5nvd