← Vulnerability feed

Vulnerability record · CVE-2017-6360 · published 23 March 2017

CVE-2017-6360: QNAP QTS OS command injection grants administrator privileges

Qnap · Qts

QNAP QTS before 4.2.4 Build 20170313 contains an OS command injection flaw (CWE-78) that lets attackers gain administrator privileges and obtain sensitive information. The advisory describes the vectors only as unspecified, so the exact injection point is not documented in this record. With a network-reachable, unauthenticated attack path and full confidentiality, integrity and availability impact, this is a severe pre-auth flaw in a widely deployed NAS operating system.

9.8 CVSS 3.0 Critical EPSS 66% · top 0.7% CWE-78 · OS command injection
9.8CVSS 3.0 base score, v2 10.0
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityPre-authentication network command injection with full CIA impact, a public exploit, and very high EPSS probability makes this an urgent patch target despite no KEV listing.

What it is

QNAP QTS before 4.2.4 Build 20170313 contains an OS command injection flaw (CWE-78) that lets attackers gain administrator privileges and obtain sensitive information. The advisory describes the vectors only as unspecified, so the exact injection point is not documented in this record. With a network-reachable, unauthenticated attack path and full confidentiality, integrity and availability impact, this is a severe pre-auth flaw in a widely deployed NAS operating system.

Impact

An attacker can execute commands with administrative rights on the device and read sensitive data, effectively taking full control of the NAS and anything it stores or connects to.

Attack surface

The CVSS vector is AV:N/AC:L/PR:N/UI:N, meaning the flaw is reachable over the network with no authentication and no user interaction. The specific interface or parameter is not identified in the description.

Exploitation

CISA KEV does not list this CVE, but a public Exploit-DB entry (41842) exists and EPSS is 0.66146 (99.24th percentile), indicating high likelihood of exploitation activity. No ransomware group is documented as using it.

What to do

  • Upgrade QNAP QTS to 4.2.4 Build 20170313 or later; this is the vendor-stated fixed build.
  • If immediate upgrade is not possible, remove the device from direct internet exposure and restrict management access to trusted networks.
  • Apply the vendor mitigation guidance referenced in the QNAP support advisory (con_show.php?cid=113).
  • Change administrator credentials and audit accounts after any suspected exposure, since the flaw yields admin privileges.
  • Monitor QNAP security advisories for follow-up fixes affecting the same QTS branch.

Detection

  • Review QTS and system logs for unexpected command execution, new admin accounts, or configuration changes on NAS devices.
  • Hunt for outbound connections or processes spawned by QTS web services that are not part of normal NAS behavior.
  • Check for the fixed build version (4.2.4 Build 20170313) across the fleet and flag any device still below it.
  • Correlate network access logs to QTS management interfaces from untrusted sources with signs of exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6360 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-2509QNAP QTS and QuTS hero command injectionQTS and QuTS hero contain a command injection flaw that lets an attacker run arbitrary commands within a compromised application. It is remotely reac…KEVEPSS 34%analysed9.8CVE-2018-19949QNAP QTS File Station command injection allows remote code executionQNAP QTS contains a command injection flaw in File Station that lets remote attackers run arbitrary commands on the NAS. It is remotely reachable wit…KEVEPSS 28%analysed9.8CVE-2019-7193QNAP QTS improper input validation allows remote code injectionQNAP QTS contains an improper input validation flaw that lets remote attackers inject arbitrary code into the system. It is remotely reachable withou…KEVEPSS 14%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed6.1CVE-2018-19953QNAP QTS File Station cross-site scripting flawQNAP QTS contains a cross-site scripting vulnerability in File Station that lets remote attackers inject malicious code. It matters because the flaw …KEVEPSS 29%analysed5.4CVE-2018-19943QNAP QTS File Station cross-site scriptingQNAP QTS contains a cross-site scripting flaw in File Station that lets a remote attacker inject malicious code. It matters because the vendor has fi…KEVEPSS 21%analysed10.0CVE-2024-32766Qnap qts command injection vulnerabilityAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2017-6360), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.