CVE-2013-0143 EXPLOIT
6.5
MEDIUM · CVSS 2.0 · EPSS 7% (pctl 94)
Patch early
A public exploit exists.
Description
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.
Scoring
| CVSS | 6.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| EPSS | 6.97% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-06-07 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| qnap | nas |
| qnap | surveillance station pro |
| qnap | viostor network video recorder |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | QNAP VioStor NVR / QNAP NAS - Remote Code Execution | 2013-06-05 |
→ the Explorer · watch your stack · NVD