This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2020-18480 | This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. |
Fixes
Solution
QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1491 build 20201119 and later QTS 4.5.1.1495 build 20201123 and later This issue does not affect QTS 4.3.x and QTS 4.2.x.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.qnap.com/en/security-advisory/qsa-20-20 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T16:28:10.857Z
Reserved: 2020-09-23T00:00:00
Link: CVE-2020-25847

No data.

Status : Modified
Published: 2020-12-29T07:15:13.213
Modified: 2024-11-21T05:18:53.777
Link: CVE-2020-25847

No data.

No data.