PT-2026-3274 · Thecus · Thecus N4800Eco Nas Server

Published

2026-01-16

·

Updated

2026-01-16

·

CVE-2021-47816

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Thecus N4800Eco NAS Server versions (affected versions not specified)
Description An authenticated attacker can execute arbitrary system commands through user management endpoints. The issue allows command injection via the username and batch user creation parameters, enabling the execution of shell commands with administrative privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-47816

Affected Products

Thecus N4800Eco Nas Server