Softnas develops cloud-based network storage solutions, with a narrow but specialized product footprint centered on its cloud storage platform. The observed vulnerability pattern reflects the product's command-line interface and system-level integration points, with disclosures clustering around OS command injection and incomplete input handling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Softnas over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14417CRITICAL A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' p | Aug 4, 2018 | 9.8 | 85 | NO | YES |
CVE-2019-9945CRITICAL SoftNAS Cloud 4.2.0 and 4.2.1 allows remote command execution. The NGINX default configuration file has a check to verify the status of a user cookie. If not set, a user is redirec | Mar 23, 2019 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Softnas.
Media articles that mention a CVE ID that affects a product developed by Softnas — matched by CVE ID, not by vendor name.