An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands.
We have already fixed the vulnerability in the following version:
Video Station 5.8.2 and later
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-24-24 |
|
History
Thu, 12 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap Systems
Qnap Systems video Station |
|
| Vendors & Products |
Qnap Systems
Qnap Systems video Station |
Wed, 11 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Mar 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later | |
| Title | Video Station | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published: 2026-03-11T08:02:09.214Z
Updated: 2026-03-11T13:52:24.375Z
Reserved: 2026-03-09T01:19:42.128Z
Link: CVE-2024-14025
Updated: 2026-03-11T13:52:19.088Z
Status : Awaiting Analysis
Published: 2026-03-11T08:16:02.747
Modified: 2026-03-11T13:52:47.683
Link: CVE-2024-14025
No data.