CVE-2023-39299

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network.

We have already fixed the vulnerability in the following versions:
Music Station 4.8.11 and later
Music Station 5.1.16 and later
Music Station 5.3.23 and later
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
qnapmusic_station
4.8.0 ≤
𝑥
< 4.8.11
qnapmusic_station
5.1.0 ≤
𝑥
< 5.1.16
qnapmusic_station
5.3.0 ≤
𝑥
< 5.3.23
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
qnapmusic_station
4.8.x ≤
𝑥
< 4.8.11
ADP
qnapmusic_station
5.1.x ≤
𝑥
< 5.1.16
ADP
qnapmusic_station
5.3.x ≤
𝑥
< 5.3.23
ADP