Description
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions prior to h4.5.1.1582 build 20210217.
No analysis available yet.
Remediation
Vendor Solution
QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1540 build 20210107 and later QuTS hero h4.5.1.1582 build 20210217 and later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15458 | A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions prior to h4.5.1.1582 build 20210217. |
References
| Link | Providers |
|---|---|
| https://www.qnap.com/zh-tw/security-advisory/qsa-21-29 |
|
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-09-16T22:15:54.877Z
Reserved: 2021-03-18T00:00:00.000Z
Link: CVE-2021-28802
No data.
Status : Modified
Published: 2021-07-01T02:15:07.317
Modified: 2024-11-21T06:00:13.903
Link: CVE-2021-28802
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD