An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later
History

Thu, 12 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Qnap Systems
Qnap Systems video Station
Vendors & Products Qnap Systems
Qnap Systems video Station

Wed, 11 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Mar 2026 09:30:00 +0000

Type Values Removed Values Added
References

Wed, 11 Mar 2026 08:30:00 +0000

Type Values Removed Values Added
References

Wed, 11 Mar 2026 08:15:00 +0000

Type Values Removed Values Added
Description An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later
Title Video Station
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 0.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2026-03-11T13:52:24.375Z

Reserved: 2026-03-09T01:19:42.128Z

Link: CVE-2024-14025

cve-icon Vulnrichment

Updated: 2026-03-11T13:52:19.088Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-11T08:16:02.747

Modified: 2026-03-11T13:52:47.683

Link: CVE-2024-14025

cve-icon Redhat

No data.