Subscribe via feed.

QNAP Q'Center change_passwd Command Execution

Posted by deepcore on July 17, 2018 – 11:35 pm

This Metasploit module exploits a command injection vulnerability in the change_passwd API method within the web interface of QNAP Q’Center virtual appliance versions prior to 1.7.1083. The vulnerability allows the ‘admin’ privileged user account to execute arbitrary commands as the ‘admin’ operating system user. Valid credentials for the ‘admin’ user account are required, however, this module also exploits a separate password disclosure issue which allows any authenticated user to view the password set for the ‘admin’ user during first install. This Metasploit module has been tested successfully on QNAP Q’Center appliance version 1.6.1075.


This post is under “exploit” and has no respond so far.
If you enjoy this article, make sure you subscribe to my RSS Feed.

Post a reply

You must be logged in to post a comment.