CVE-2013-0143
Last modified
CVE-2013-0143 is a vulnerability of currently unknown severity. cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.. EPSS estimates a 6.97% chance of exploitation in the next 30 days.
Description
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qnap | Viostor Network Video Recorder | 4.0.3 |
| Qnap | Viostor Network Video Recorder | All versions |
| Qnap | Surveillance Station Pro | All versions |
| Qnap | Nas | All versions |
References
- http://www.kb.cert.org/vuls/id/927644US Government Resource
- http://www.kb.cert.org/vuls/id/927644US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-0143?
How severe is CVE-2013-0143?
How do I fix CVE-2013-0143?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-0137The default configuration of the Digital Alert Systems DASDE…
- CVE-2013-0138BitZipper 2013 before Update 1 allows remote attackers to ex…
- CVE-2013-0139The Arecont Vision AV1355DN MegaDome camera allows remote at…
- CVE-2013-0140SQL injection vulnerability in the Agent-Handler component i…
- CVE-2013-0141Directory traversal vulnerability in McAfee ePolicy Orchestr…
- CVE-2013-0142QNAP VioStor NVR devices with firmware 4.0.3, and the Survei…
- CVE-2013-0144Cross-site request forgery (CSRF) vulnerability in cgi-bin/c…
- CVE-2013-0145Buffer overflow in the TFTPD service in Serva32 2.1.0 allows…
- CVE-2013-0148The Data Camouflage (aka FairCom Standard Encryption) algori…
- CVE-2013-0149The OSPF implementation in Cisco IOS 12.0 through 12.4 and 1…
- CVE-2013-0150Directory traversal vulnerability in an unspecified signed J…
- CVE-2013-0151The do_hvm_op function in xen/arch/x86/hvm/hvm.c in Xen 4.2.…
Are you affected by CVE-2013-0143?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
