← Vulnerability feed

Vulnerability record · CVE-2018-0706 · published 17 July 2018

CVE-2018-0706: QNAP Q'center Virtual Appliance private information exposure

Qnap · Q\'Center

QNAP Q'center Virtual Appliance version 1.7.1063 and earlier exposes private information, allowing authenticated users to reach sensitive data. The record does not specify which data or endpoint is affected, so the exact scope of exposure is unclear. It matters because the appliance is a management component, and leaked information can support further attacks.

8.8 CVSS 3.0 High EPSS 48% · top 1.2%
8.8CVSS 3.0 base score, v2 4.0
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access sensitive information.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 8.8, public exploit references and a very high EPSS percentile make this a high-priority item despite the lack of KEV listing.

What it is

QNAP Q'center Virtual Appliance version 1.7.1063 and earlier exposes private information, allowing authenticated users to reach sensitive data. The record does not specify which data or endpoint is affected, so the exact scope of exposure is unclear. It matters because the appliance is a management component, and leaked information can support further attacks.

Impact

An authenticated attacker gains access to sensitive information held by the appliance. The CVSS vector also rates high confidentiality, integrity and availability impact, but the record does not explain how integrity or availability are affected.

Attack surface

The flaw is reachable over the network with low privileges and no user interaction, per the CVSS vector AV:N/AC:L/PR:L/UI:N. Authentication as a low-privileged user is required.

Exploitation

Public exploit references exist, including Exploit-DB entries and a Core Security advisory, and EPSS is 0.48688 (98.8th percentile). CISA KEV does not list it.

What to do

  • Upgrade Q'center Virtual Appliance beyond version 1.7.1063 per the QNAP vendor advisory.
  • Restrict network access to the Q'center management interface to trusted administrators only.
  • Review and remove unnecessary low-privileged accounts on the appliance.
  • Monitor for and rotate any credentials or secrets that may have been exposed.

Detection

  • Audit access logs for authenticated requests to Q'center endpoints that return sensitive data.
  • Alert on unusual low-privileged account activity or enumeration of management interfaces.
  • Watch for exploitation attempts matching the published Exploit-DB and Core Security proof-of-concept traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0706 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2018-0706), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.