安全ID : QSA-25-57
Multiple Vulnerabilities in Media Streaming add-on
发布日期 : February 12, 2026
通用漏洞披露 : CVE-2024-56807 | CVE-2024-56808
受影响产品: Media Streaming add-on 500.1.x
严重程度
Moderate
状态
已解决
Summary
Multiple vulnerabilities have been reported to affect Media Streaming add-on:
- CVE-2024-56807: Out-of-bounds read vulnerability
If an attacker gains access to the local network, they can then exploit the vulnerability to obtain secret data. - CVE-2024-56808: Command injection vulnerability
If an attacker gains access to the local network and a user account, they can then exploit the vulnerability to execute arbitrary commands
We have already fixed the vulnerabilities in the following version:
| Affected Product | Fixed Version |
| Media Streaming add-on 500.1.x | Media Streaming add-on 500.1.1.6 (2024/08/02) and later |
Recommendation
To fix the vulnerabilities, we recommend updating Media Streaming add-on to the latest version.
Updating Media Streaming add-on
- Log on to QTS or QuTS hero as an administrator.
- Open App Center and then click
.
A search box appears. - Type "Media Streaming add-on" and then press ENTER.
Media Streaming add-on appears in the search results. - Click Update.
A confirmation message appears.
Note: The Update button is not available if your Media Streaming add-on is already up to date. - Click OK.
The system updates the application.
附件
致谢: dcs
修订历史:
V1.0 (February 12, 2026) - Published