PT-2021-5431 · Qnap · Qnap Qvr

Jpcert/Cc

·

Published

2021-11-26

·

Updated

2021-12-02

·

CVE-2021-38685

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QNAP QVR versions prior to 5.1.6 build 20211109
Description A command injection issue affects QNAP QVR, related to the failure to neutralize special elements used in an OS command. This allows a remote attacker to execute arbitrary commands. The vulnerability can be exploited by remote attackers to run arbitrary commands.
Recommendations For QNAP QVR versions prior to 5.1.6 build 20211109, update to QVR FW 5.1.6 build 20211109 or later to resolve the issue. As a temporary workaround, consider restricting access to vulnerable components until a patch is applied.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-06274
CVE-2021-38685

Affected Products

Qnap Qvr