The web-management application on Seagate Central NAS...
Critical severity
Unreviewed
Published
Dec 6, 2022
to the GitHub Advisory Database
•
Updated Apr 23, 2025
Description
Published by the National Vulnerability Database
Dec 6, 2022
Published to the GitHub Advisory Database
Dec 6, 2022
Last updated
Apr 23, 2025
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.
References