A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:HQnap Qgd 1600p
HWQnapall versionsQnap Qgd 1602p
HWQnapall versionsQnap Qgd 3014pt
HWQnapall versionsQnap Qsw M2116p 2t2s
HWQnapall versionsQnap Qsw M2116p 2t2s Firmware
OSQnap< 1.0.6Qnap Qunetswitch
APPQnap< 1.0.6.1509
Related vulnerabilities
A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then explo...
W produkcie QuNetSwitch ujawniono lukę związaną z hard-coded credentials, która może pozwolić atakującym na zd...
W produkcie QuNetSwitch ujawniona została luka podatności command injection. Jeśli atakujący zdalnie uzyska do...
W QuNetSwitch wykryta została podatność command injection. Jeśli lokalny atakujący uzyska dostęp do konta admi...
QNAP Photo Station — niekontrolowane odniesienie do zewnętrznego zasobu (RCE/modyfikacja plików)