CVE-2014-5457: QNAP Ss-839
Low severity, CVSS 2.1. EPSS: 0.3% chance of exploitation in the next 30 days.
QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.
Affected products
- QNAP Ss-839
- QNAP Ss-839 Firmware: version 4.0.7 only
- QNAP Ts-459u
- QNAP Ts-459u Firmware: version 4.0.7 only
- QNAP Ts-469u
- QNAP Ts-469u Firmware: version 4.0.7 only
- QNAP Ts-EC1679U-Rp
- QNAP Ts-EC1679U-Rp Firmware: version 4.0.7 only
Published 2014-08-25. Last modified 2026-06-17.