An OS command injection vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following version:
Media Streaming add-on 500.1.1.5 ( 2024/01/22 ) and later
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-24-15 |
|
History
Mon, 08 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:qnap:media_streaming_add-on:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: qnap
Published: 2024-05-03T02:32:04.674Z
Updated: 2024-08-02T21:01:22.912Z
Reserved: 2023-11-03T09:47:36.054Z
Link: CVE-2023-47220
Updated: 2024-05-21T15:05:53.923Z
Status : Analyzed
Published: 2024-05-03T03:16:01.977
Modified: 2025-12-08T19:30:38.580
Link: CVE-2023-47220
No data.