CVE-2020-2494: QNAP Music Station

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12 and later

Affected products

  • QNAP Music Station: before 5.3.13 (fixed in 5.3.13); before 5.3.12 (fixed in 5.3.12)

Published 2020-12-10. Last modified 2026-06-17.