Back

CVE-2018-0712

CRITICAL

Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.

Published: Jun 21, 2018 Modified: Jun 17, 2026
CWE-77

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
qnap qts 4.2.6
qnap qts 4.3.3
qnap qts *

GitHub Security Advisory GHSA-66p6-q85w-xp92

Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 2.64%

Top 16% most likely to be exploited

Threat Score 40 / 100

Data Sources

NVD EPSS GitHub