Impact
The vulnerability is a cross‑site scripting flaw in QcalAgent that allows an attacker who has local access to inject malicious scripts into the application. By exploiting this flaw the attacker can bypass built‑in security controls or read protected application data. This is a typical client‑side injection weakness classified as CWE‑79.
Affected Systems
The issue affects QNAP Systems Inc.'s QcalAgent component. All released versions prior to 1.1.9 contain the vulnerability; versions 1.1.9 and later contain the fix.
Risk and Exploitability
The CVSS score of 5.2 indicates a medium severity. The EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis, and the flaw is not yet listed in CISA’s KEV catalog. The likely attack vector is local; an adversary with physical or administrative access to the device can submit crafted requests that trigger the XSS. Once executed, the injected script can use the browser context to read cookies, session tokens, and other data exposed by QcalAgent, potentially allowing further privilege escalation.
OpenCVE Enrichment