First published: Tue Dec 29 2020(Updated: )
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | <4.5.1.1495 | |
QNAP QuTS hero | <h4.5.1.1491 |
QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1491 build 20201119 and later QTS 4.5.1.1495 build 20201123 and later This issue does not affect QTS 4.3.x and QTS 4.2.x.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25847 is a command injection vulnerability that allows attackers to execute arbitrary commands in a compromised application.
CVE-2020-25847 has a severity value of 8.8, which is considered high.
Versions of QTS up to and excluding 4.5.1.1495 and versions of QuTS hero up to and excluding h4.5.1.1491 are affected by CVE-2020-25847.
Yes, QNAP has already fixed this vulnerability in the following versions of QTS and QuTS hero.
More information about CVE-2020-25847 can be found at the following link: [https://www.qnap.com/en/security-advisory/qsa-20-20](https://www.qnap.com/en/security-advisory/qsa-20-20)