An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands.
We have already fixed the vulnerability in the following version:
Video Station 5.8.2 and later
We have already fixed the vulnerability in the following version:
Video Station 5.8.2 and later
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-24-24 |
|
History
Wed, 11 Mar 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Mar 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later | |
| Title | Video Station | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2026-03-11T08:06:46.753Z
Reserved: 2026-03-09T01:19:42.128Z
Link: CVE-2024-14025
No data.
Status : Received
Published: 2026-03-11T08:16:02.747
Modified: 2026-03-11T09:16:11.820
Link: CVE-2024-14025
No data.
OpenCVE Enrichment
No data.
Weaknesses