VendorsQNAPmusic_stationall versions
Vulnerabilities

QNAP Music Station

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2018-0729
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.
Published 2019-12-04 · Modified
9.8EPSS 0.023
CVE-2018-19950
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Published 2020-11-02 · Modified
9.8EPSS 0.021
CVE-2017-13069
QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a remote attacker to run arbitrary commands on the NAS.
Published 2017-10-06 · Modified
9.8EPSS 0.017
CVE-2018-0718
Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary commands in the compromised application.
Published 2018-09-14 · Modified
9.8EPSS 0.017
CVE-2020-36197
Improper Access Control Vulnerability in Music Station
Published 2021-05-13 · Modified
8.8EPSS 0.185
CVE-2023-45038
Music Station
Published 2024-09-06 · Analyzed
8.8EPSS 0.012
CVE-2023-23365
Music Station
Published 2023-10-06 · Modified
7.7EPSS 0.006
CVE-2023-23366
Music Station
Published 2023-10-06 · Modified
7.7EPSS 0.006
CVE-2018-19952
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Published 2020-11-02 · Modified
7.5EPSS 0.013
CVE-2023-39299
Music Station
Published 2023-11-03 · Modified
7.5EPSS 0.006
CVE-2020-2494
Cross-site Scripting Vulnerability in Music Station
Published 2020-12-10 · Modified
6.1EPSS 0.010
CVE-2018-19951
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Published 2020-11-02 · Modified
6.1EPSS 0.008
CVE-2019-7185
This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.
Published 2019-12-05 · Modified
4.8EPSS 0.015