Critical severity9.8NVD Advisory· Published Nov 28, 2018· Updated Jun 17, 2026
CVE-2018-14746
CVE-2018-14746
Description
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to run arbitrary commands on the NAS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:o:qnap:qts:4.2.6:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:qnap:qts:4.2.6:*:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:4.3.3:*:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:4.3.4:*:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:4.3.5:*:*:*:*:*:*:*
- (no CPE)range: <=4.3.5 build 20181013, <=4.3.4 build 20181008, <=4.3.3 build 20180829, <=4.2.6 build 20180829
- QNAP/QNAP QTSv5Range: QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions
Patches
Vulnerability mechanics
References
1- www.qnap.com/zh-tw/security-advisory/nas-201811-22nvdVendor Advisory
News mentions
0No linked articles in our index yet.