📦

media_streaming_add-on

Vendor: qnap

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 5 Remote Access
Total CVEs 16 Total Indexed
Avg. EPSS 1.99% Exploit Prob.
Latest CVE CVE-2025-59383 Mar 20

Security Vulnerability Index

Page 2 / 2
9.8 CVSS

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.

EPSS: 2.33%
6.5 CVSS

QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.

EPSS: 0.68%
6.1 CVSS

Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted link, not the normal page.

EPSS: 0.77%