High severity7.8NVD Advisory· Published Feb 11, 2026· Updated Jun 17, 2026
CVE-2024-56808
CVE-2024-56808
Description
A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:qnap:media_streaming_add-on:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:qnap:media_streaming_add-on:*:*:*:*:*:*:*:*range: >=500.1.1.0,<500.1.1.6
- (no CPE)range: >=500.1.1.6
- QNAP Systems Inc./Media Streaming add-onv5Range: 500.1.x
Patches
Vulnerability mechanics
References
1- www.qnap.com/en/security-advisory/qsa-25-57nvdVendor Advisory
News mentions
0No linked articles in our index yet.