ZeroHour

CVE-2021-34348

CVSS 3.1
9.8 critical
EPSS
1%p72
Published
()
Modified
Description

A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later

Vendors
qnap
Products
qvr
Weakness
CWE-78, CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.