Back
CVE-2017-13071
CRITICAL
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.
Published: Nov 22, 2017
Modified: Jun 17, 2026
CWE-77
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| qnap | video_station | 5.1.3 |
| qnap | video_station | 5.2.0 |
GitHub Security Advisory GHSA-3666-cq3x-qwx9
QNAP has already patched this vulnerability. This security concern allows a remote attacker to...
References (2)
- https://www.qnap.com/zh-tw/security-advisory/nas-201711-21 Vendor Advisory
- https://www.qnap.com/zh-tw/security-advisory/nas-201711-21 Vendor Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
1.44%
Top 29% most likely to be exploited
Threat Score
39.6 / 100
Data Sources
NVD
EPSS
GitHub