NA

CVE-2023-51365

Published: 26/04/2024 Updated: 26/04/2024

Vulnerability Summary

This vulnerability allows remote malicious users to execute arbitrary code on affected installations of QNAP TS-464 NAS devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the HLS_tmp parameter provided to the share.cgi endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create or modify files in the context of admin.

Vulnerability Trend