CVE-2017-5227: QNAP QTS
High severity, CVSS 7.5. EPSS: 6.4% chance of exploitation in the next 30 days.
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file.
Affected products
- QNAP QTS: up to and including 4.2.4
Published 2017-03-23. Last modified 2026-06-17.