Vulnerability record · CVE-2018-0706 · published 17 July 2018
CVE-2018-0706: QNAP Q'center Virtual Appliance private information exposure
Qnap · Q\'Center
QNAP Q'center Virtual Appliance version 1.7.1063 and earlier exposes private information, allowing authenticated users to reach sensitive data. The record does not specify which data or endpoint is affected, so the exact scope of exposure is unclear. It matters because the appliance is a management component, and leaked information can support further attacks.
Description
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access sensitive information.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8, public exploit references and a very high EPSS percentile make this a high-priority item despite the lack of KEV listing.
What it is
QNAP Q'center Virtual Appliance version 1.7.1063 and earlier exposes private information, allowing authenticated users to reach sensitive data. The record does not specify which data or endpoint is affected, so the exact scope of exposure is unclear. It matters because the appliance is a management component, and leaked information can support further attacks.
Impact
An authenticated attacker gains access to sensitive information held by the appliance. The CVSS vector also rates high confidentiality, integrity and availability impact, but the record does not explain how integrity or availability are affected.
Attack surface
The flaw is reachable over the network with low privileges and no user interaction, per the CVSS vector AV:N/AC:L/PR:L/UI:N. Authentication as a low-privileged user is required.
Exploitation
Public exploit references exist, including Exploit-DB entries and a Core Security advisory, and EPSS is 0.48688 (98.8th percentile). CISA KEV does not list it.
What to do
- Upgrade Q'center Virtual Appliance beyond version 1.7.1063 per the QNAP vendor advisory.
- Restrict network access to the Q'center management interface to trusted administrators only.
- Review and remove unnecessary low-privileged accounts on the appliance.
- Monitor for and rotate any credentials or secrets that may have been exposed.
Detection
- Audit access logs for authenticated requests to Q'center endpoints that return sensitive data.
- Alert on unusual low-privileged account activity or enumeration of management interfaces.
- Watch for exploitation attempts matching the published Exploit-DB and Core Security proof-of-concept traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-0706 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0706), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.