CVE-2014-3206: Seagate Blackarmor NAS 110 Firmware

Critical severity, CVSS 9.8. EPSS: 51% chance of exploitation in the next 30 days.

Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.

Affected products

  • Seagate Blackarmor NAS 110 Firmware: affected versions not specified
  • Seagate Blackarmor NAS 220 Firmware: affected versions not specified

Published 2018-02-23. Last modified 2026-06-17.