Loading vulnerability details…
CVSS v3.1
7.3
EPSS
1.98%
Published
Feb 3, 2021
Modified
Oct 27, 2025
CISA Known Exploited Vulnerability
Added: 2022-03-25 · Due: 2022-04-15
Apply updates per vendor instructions.
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LWeaknesses (CWE)
Affected Products (1)
References (3)