Back

CVE-2017-13067

CRITICAL

QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerability allows a remote attacker to execute commands on a QNAP NAS using a transcoding service on port 9251. A remote user does not require any privileges to successfully execute an attack.

Published: Sep 14, 2017 Modified: Jun 17, 2026
NVD-CWE-noinfo

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (2)

Vendor Product Version
qnap qts * ≥ 4.2.0
qnap qts * ≥ 4.3.0

GitHub Security Advisory GHSA-w5c8-52mf-vw3c

QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 16.68%

Top 3% most likely to be exploited

Threat Score 44.2 / 100

Data Sources

NVD EPSS GitHub