CVE-2014-5457: QNAP Ss-839

Low severity, CVSS 2.1. EPSS: 0.3% chance of exploitation in the next 30 days.

QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.

Affected products

  • QNAP Ss-839
  • QNAP Ss-839 Firmware: version 4.0.7 only
  • QNAP Ts-459u
  • QNAP Ts-459u Firmware: version 4.0.7 only
  • QNAP Ts-469u
  • QNAP Ts-469u Firmware: version 4.0.7 only
  • QNAP Ts-EC1679U-Rp
  • QNAP Ts-EC1679U-Rp Firmware: version 4.0.7 only

Published 2014-08-25. Last modified 2026-06-17.