CVE-2015-7261

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
27/02/2016
Last modified:
12/04/2025

Description

The FTP service in QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, has hardcoded credentials, which makes it easier for remote attackers to obtain access via a session on TCP port 21.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qnap:iartist_lite:*:*:*:*:*:*:*:* 1.4.53.1 (including)
cpe:2.3:a:qnap:signage_station:*:*:*:*:*:*:*:* 2.0 (including)