Command Injection Risk in Media Streaming Add-on by QNAP
CVE-2024-56808
2LOW
What is CVE-2024-56808?
A command injection vulnerability has been identified in the Media Streaming add-on from QNAP. If an attacker with established user credentials gains local network access, they can exploit this vulnerability to execute arbitrary commands. This poses significant risks to the integrity and confidentiality of the system. It's essential to update to Media Streaming add-on version 500.1.1.6 or later to mitigate this risk.
Affected Version(s)
Media Streaming add-on 500.1.x < 500.1.1.6 ( 2024/08/02 )