CVE-2023-23365: QNAP Music Station

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: Music Station 5.3.22 and later

Affected products

  • QNAP Music Station: from 5.3.0, before 5.3.22 (fixed in 5.3.22)

Published 2023-10-06. Last modified 2026-06-17.