peter bassill · operator
$ cve CVE-2013-0143 JSON

CVE-2013-0143 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 7% (pctl 94)

Patch early

A public exploit exists.

Description

cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS6.97% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2013-06-07
Last modified2026-06-16

Affected (3)

VendorProduct
qnapnas
qnapsurveillance station pro
qnapviostor network video recorder

Public exploits

SourceTitleDate
exploit-dbQNAP VioStor NVR / QNAP NAS - Remote Code Execution2013-06-05

References

→ the Explorer  ·  watch your stack  ·  NVD