CVE-2024-14025 PUBLISHED

Video Station

Assigner: qnap
Reserved: 09.03.2026 Published: 11.03.2026 Updated: 11.03.2026

An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands.

We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later

Metrics

CVSS Vector: CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:U
CVSS Score: 0.1

Product Status

Vendor QNAP Systems Inc.
Product Video Station
Versions Default: unaffected
  • affected from 5.8.x to 5.8.2 (excl.)

Solutions

We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later

References

Problem Types

  • CWE-89 CWE

Impacts

  • CAPEC-108