← Back

CVE-2013-0143

nvd nist
Published: Jun 7, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.

Affected (4)

3 products
Viostor Network Video Recorder
Nas
Surveillance Station Pro
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.0.3
All versions
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions

References (2)

Source: cret@cert.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource

Timeline

No history available yet.