CVE-2013-0143: QNAP NAS

Medium severity, CVSS 6.5. EPSS: 7% chance of exploitation in the next 30 days.

cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.

Affected products

  • QNAP NAS: affected versions not specified
  • QNAP Surveillance Station Pro: affected versions not specified
  • QNAP VioStor Network Video Recorder: version 4.0.3 only

Published 2013-06-07. Last modified 2026-06-16.