\QNAP Music Station/Malware... CVE-2020-36197 CVE-2020-36198

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# QNAP MusicStation/MalwareRemover Pre-Auth Remote Code Execution ## Summary QNAP MusicStation and MalwareRemover official apps are affected by an arbitrary file upload and a command injection vulnerabilities, leading to pre-auth remote root command execution. ## Product description (from vendor) “QNAP (Quality Network Appliance Provider) is devoted to providing comprehensive solutions in software development, hardware design and in-house manufacturing.”. For more information visit https://qnap.com/. ## CVE(s) - [CVE-2020-36197](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36197) - [CVE-2020-36198](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36198) ## Details ### Root cause analysis #### Pre-auth arbitrary file write in MusicStation “Music Station is a web-based music player for users to enjoy their music collection on the NAS.” from QNAP App Center. MusicStation is not pre-installed on the QNAP device, but it is one of the most popular apps in the QNAP...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息