CVE-2013-10049
Published: Aug 1, 2025
Modified: Apr 7, 2026
Description
An OS command injection vulnerability exists in multiple Raidsonic NAS devices—specifically tested on IB-NAS5220 and IB-NAS4220—via the unauthenticated timeHandler.cgi endpoint exposed through the web interface. The CGI script fails to properly sanitize user-supplied input in the timeZone parameter of a POST request, allowing remote attackers to inject arbitrary shell commands.
| Vendor | Product | Versions |
|---|---|---|
Raidsonic Technology GmbH | IB-NAS5220 | affected * |
Raidsonic Technology GmbH | IB-NAS4220 | affected * |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now