PoC Index

CVE-2023-47218

HIGH 8.3EPSS 89.9%

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.We have already fixed the vulnerability in the following versions:QTS 5.1.5.2645 build 20240116 and laterQuTS hero h5.1.5.2647 build 20240118 and laterQuTScloud c5.1.5.2651 and later

CVSS v3.1
8.3 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
CVSS v3.1
5.8 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
EPSS
89.92% chance of exploitation in the next 30 days, 100th percentile
Nuclei
medium · CWE-77
Published
2024-02-13
Updated
2025-05-07

Proof-of-concept exploits (2)

Nuclei templates (1)

Metasploit modules (1)

References

Related