Description
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions prior to h4.5.1.1582 build 20210217.
No analysis available yet.
Remediation
Vendor Solution
QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1540 build 20210107 and later QuTS hero h4.5.1.1582 build 20210217 and later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15460 | A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions prior to h4.5.1.1582 build 20210217. |
References
| Link | Providers |
|---|---|
| https://www.qnap.com/zh-tw/security-advisory/qsa-21-29 |
|
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-09-16T16:54:06.578Z
Reserved: 2021-03-18T00:00:00.000Z
Link: CVE-2021-28804
No data.
Status : Modified
Published: 2021-07-01T02:15:07.447
Modified: 2024-11-21T06:00:14.120
Link: CVE-2021-28804
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD