peter bassill · operator
$ cve CVE-2017-7876 JSON

CVE-2017-7876

10.0
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and later versions.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS3.34% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2017-06-15
Last modified2026-06-17

Affected (1)

VendorProduct
qnapqts

References

→ the Explorer  ·  watch your stack  ·  NVD