vendor:
QTS and Photo Station 6.0.3
by:
Yunus YILDIRIM (Th3Gundy)
9.8
CVSS
CRITICAL
Remote Command Execution
20
CWE
Product Name: QTS and Photo Station 6.0.3
Affected Version From: QTS < 4.4.1
Affected Version To: Photo Station < 6.0.3
Patch Exists: YES
Related CWE: CVE-2019-7192, CVE-2019-7193, CVE-2019-7194, CVE-2019-7195
CPE: a:qnap:qts
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2020
QNAP QTS and Photo Station 6.0.3 – Remote Command Execution
This exploit allows an attacker to execute arbitrary commands on vulnerable QNAP QTS and Photo Station 6.0.3 devices. The vulnerability exists due to improper validation of user-supplied input in the web application. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. Successful exploitation of this vulnerability can result in unauthorized access to the application.
Mitigation:
Users should update their QNAP QTS and Photo Station 6.0.3 devices to the latest version.