Show filters
194 Total Results
Displaying 31-40 of 194
Sort by:
Attacker Value
Unknown
CVE-2022-4221
Disclosure Date: December 01, 2022 (last updated November 08, 2023)
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.
0
Attacker Value
Unknown
CVE-2022-23771
Disclosure Date: October 17, 2022 (last updated October 08, 2023)
This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker can use this vulnerability to or delete user accounts, or to escalate arbitrary user privileges.
0
Attacker Value
Unknown
CVE-2022-34747
Disclosure Date: September 06, 2022 (last updated October 08, 2023)
A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet.
0
Attacker Value
Unknown
CVE-2022-23765
Disclosure Date: August 17, 2022 (last updated October 08, 2023)
This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the root through a POST request.
0
Attacker Value
Unknown
CVE-2022-31109
Disclosure Date: August 01, 2022 (last updated October 08, 2023)
laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP message factory interfaces. Applications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a `Laminas\Diactoros\Uri` instance associated with the incoming server request modified to reflect values from `X-Forwarded-*` headers. Such changes can potentially lead to XSS attacks (if a fully-qualified URL is used in links) and/or URL poisoning. Since the `X-Forwarded-*` headers do have valid use cases, particularly in clustered environments using a load balancer, the library offers mitigation measures only in the v2 releases, as doing otherwise would break these use cases immediately. Users of v2 releases from 2.11.1 can provide an additional argument to `Laminas\Diactoros\ServerRequestFactory::fromGlobals()` in the form of a `Laminas\Diactoros\RequestFilter\RequestFilterInte…
0
Attacker Value
Unknown
CVE-2021-40660
Disclosure Date: June 14, 2022 (last updated October 07, 2023)
An issue was discovered in Delight Nashorn Sandbox 0.2.0. There is an ReDoS vulnerability that can be exploited to launching a denial of service (DoS) attack.
0
Attacker Value
Unknown
CVE-2022-32268
Disclosure Date: June 03, 2022 (last updated November 29, 2024)
StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST command, which allows changing the hostname, doesn’t check a new hostname parameter. It goes directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into the command that will be executed with root privileges.
0
Attacker Value
Unknown
CVE-2021-34360
Disclosure Date: May 26, 2022 (last updated October 07, 2023)
A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later
0
Attacker Value
Unknown
CVE-2021-26620
Disclosure Date: March 25, 2022 (last updated February 23, 2025)
An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.
0
Attacker Value
Unknown
CVE-2022-26660
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
RunAsSpc 4.0 uses a universal and recoverable encryption key. In possession of a file encrypted by RunAsSpc, an attacker can recover the credentials that were used.
0