PT-2013-2129 · Qnap · Surveillance Station+2

David Elze

+1

·

Published

2013-06-07

·

Updated

2013-06-10

·

CVE-2013-0143

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions QNAP VioStor NVR devices version 4.0.3 QNAP NAS (affected versions not specified), specifically in the Surveillance Station Pro component
Description The issue allows remote authenticated users to execute arbitrary commands. This is achieved by leveraging guest access and placing shell metacharacters in the query string of the 'cgi-bin/pingping.cgi' endpoint.
Recommendations For QNAP VioStor NVR devices version 4.0.3, update the firmware to a version that addresses this issue. For QNAP NAS with the Surveillance Station Pro component, restrict access to the 'cgi-bin/pingping.cgi' endpoint until a fix is available. As a temporary workaround, consider disabling guest access to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0143

Affected Products

Qnap Nas
Qnap Viostor Nvr
Surveillance Station