The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.
2022-12-06T15:15:15.730
2025-04-23T15:15:46.020
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | seagate | stcg2000300_firmware | - | Yes |
Hardware | seagate | stcg2000300 | - | No |
Operating System | seagate | stcg3000300_firmware | - | Yes |
Hardware | seagate | stcg3000300 | - | No |
Operating System | seagate | stcg4000300_firmware | - | Yes |
Hardware | seagate | stcg4000300 | - | No |