This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qts | Qnap | 4.2.6 (including) | 4.2.6 (including) |
Qts | Qnap | 4.3.3.0868 (including) | 4.3.3.0868 (including) |
Qts | Qnap | 4.3.3.0998 (including) | 4.3.3.0998 (including) |
Qts | Qnap | 4.3.4.0899 (including) | 4.3.4.0899 (including) |
Qts | Qnap | 4.3.4.1029 (including) | 4.3.4.1029 (including) |
Qts | Qnap | 4.3.6.0895 (including) | 4.3.6.0895 (including) |
Qts | Qnap | 4.3.6.0907 (including) | 4.3.6.0907 (including) |
Qts | Qnap | 4.3.6.0923 (including) | 4.3.6.0923 (including) |
Qts | Qnap | 4.3.6.0944 (including) | 4.3.6.0944 (including) |
Qts | Qnap | 4.3.6.0959 (including) | 4.3.6.0959 (including) |
Qts | Qnap | 4.3.6.0979 (including) | 4.3.6.0979 (including) |
Qts | Qnap | 4.3.6.0993 (including) | 4.3.6.0993 (including) |
Qts | Qnap | 4.3.6.1013 (including) | 4.3.6.1013 (including) |
Qts | Qnap | 4.3.6.1033 (including) | 4.3.6.1033 (including) |
Qts | Qnap | 4.4.1.0948-beta (including) | 4.4.1.0948-beta (including) |
Qts | Qnap | 4.4.1.0949-beta (including) | 4.4.1.0949-beta (including) |
Qts | Qnap | 4.4.1.0978-beta_2 (including) | 4.4.1.0978-beta_2 (including) |
Qts | Qnap | 4.4.1.0998-beta_3 (including) | 4.4.1.0998-beta_3 (including) |
Qts | Qnap | 4.4.1.0999-beta_3 (including) | 4.4.1.0999-beta_3 (including) |
Qts | Qnap | 4.4.1.1031-beta_4 (including) | 4.4.1.1031-beta_4 (including) |
Qts | Qnap | 4.4.1.1033-beta_4 (including) | 4.4.1.1033-beta_4 (including) |
Qts | Qnap | 4.4.1.1064 (including) | 4.4.1.1064 (including) |
Qts | Qnap | 4.4.1.1081 (including) | 4.4.1.1081 (including) |
Qts | Qnap | 4.4.1.1086 (including) | 4.4.1.1086 (including) |
Qts | Qnap | 4.4.1.1101 (including) | 4.4.1.1101 (including) |