QNAP Systems Music Station是中国威联通科技(QNAP Systems)公司的一款音乐播放和管理应用程序。 QNAP Systems Music Station 5.4.0版本及之前版本存在授权问题漏洞,该漏洞源于包含一个不正确的身份验证漏洞。攻击者利用该漏洞可以通过网络危害系统的安全。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| QNAP Systems Inc. | Music Station | 5.4.x ~ 5.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Music Station 5.4.0 and later | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-45038.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-21897 | 8.9 HIGH | QTS, QuTS hero |
| CVE-2023-50360 | 8.8 HIGH | Video Station |
| CVE-2024-21898 | 8.8 HIGH | QTS, QuTS hero |
| CVE-2023-34974 | 8.8 HIGH | QTS, QuTS hero, QuTScloud, QVR, QES |
| CVE-2023-51366 | 8.7 HIGH | QTS, QuTS hero |
| CVE-2024-32762 | 8.2 HIGH | QuLog Center |
| CVE-2023-39298 | 7.8 HIGH | QTS, QuTS hero |
| CVE-2023-47563 | 7.4 HIGH | Video Station |
| CVE-2023-39300 | 7.2 HIGH | QTS |
| CVE-2022-27592 | 6.7 MEDIUM | QVR Smart Client |
| CVE-2023-34979 | 6.6 MEDIUM | QTS, QuTS hero |
| CVE-2024-21903 | 6.6 MEDIUM | QTS, QuTS hero |
| CVE-2024-27126 | 6.3 MEDIUM | Notes Station 3 |
| CVE-2024-27122 | 6.3 MEDIUM | Notes Station 3 |
| CVE-2024-21904 | 5.9 MEDIUM | QTS, QuTS hero |
| CVE-2023-51368 | 5.4 MEDIUM | QTS, QuTS hero |
| CVE-2023-51367 | 5.4 MEDIUM | QTS, QuTS hero |
| CVE-2024-21906 | 4.7 MEDIUM | QTS, QuTS hero |
| CVE-2023-50366 | 4.3 MEDIUM | QTS, QuTS hero |
| CVE-2024-27125 | 3.5 LOW | Helpdesk |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet