CVE-2017-10700: QNAP QTS

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.

Affected products

  • QNAP QTS: version 4.3.3.0229 only

Published 2017-09-19. Last modified 2026-06-17.