CVE-2018-0730 is a critical command injection vulnerability in QNAP QTS File Station, allowing unauthenticated remote attackers to execute arbitrary commands on affected devices. With a CVSS score of 9.8, this vulnerability presents a severe risk, enabling full compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness among security researchers. QNAP recommends updating QTS to the latest versions to mitigate this threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.6CPE matchmatch criteria | cpe:2.3:o:qnap:qts:4.2.6:*:*:*:*:*:*:* | ||
4.3.3.0868CPE matchmatch criteria | cpe:2.3:o:qnap:qts:4.3.3.0868:*:*:*:*:*:*:* | ||
4.3.3.0998CPE matchmatch criteria | cpe:2.3:o:qnap:qts:4.3.3.0998:*:*:*:*:*:*:* | ||
4.3.4.0899CPE matchmatch criteria | cpe:2.3:o:qnap:qts:4.3.4.0899:*:*:*:*:*:*:* | ||
4.3.4.1029CPE matchmatch criteria | cpe:2.3:o:qnap:qts:4.3.4.1029:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.