PT-2025-49395 · Sgai · Space1 Nas N1211Ds

Renguangyue

·

Published

2025-12-07

·

Updated

2025-12-09

·

CVE-2025-14184

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SGAI Space1 NAS N1211DS versions through 1.0.915
Description A command injection issue exists in the gsaiagent component. The RENAME FILE/OPERATE FILE/NGNIX UPLOAD function within the /cgi-bin/JSONAPI file is susceptible to manipulation, leading to command injection. This attack can be initiated remotely. The exploit has been publicly disclosed. The vendor was contacted regarding this disclosure but did not respond.
Recommendations Versions through 1.0.915: As a temporary workaround, consider restricting access to the /cgi-bin/JSONAPI file to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-14184

Affected Products

Space1 Nas N1211Ds