First published: Thu Jun 03 2021(Updated: )
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2; versions prior to 5.5.4 on QuTS hero h4.5.2; versions prior to 5.5.4 on QuTScloud c4.5.4. This issue does not affect: QNAP Systems Inc. Video Station on QTS 4.3.6; on QTS 4.3.3.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Video Station | <5.5.4 | |
QNAP QTS | =4.5.2 | |
QNAP QuTS hero | =h4.5.2 | |
QNAP QuTScloud | =c4.5.4 |
QNAP have already fixed the issue in the following versions: QTS 4.5.2: Video Station 5.5.4 and later QuTS hero h4.5.2: Video Station 5.5.4 and later QuTScloud c4.5.4: Video Station 5.5.4 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28812 is a command injection vulnerability that affects certain versions of QNAP Video Station.
CVE-2021-28812 can be exploited by remote attackers to execute arbitrary commands.
Versions of Video Station prior to 5.5.4 on QTS 4.5.2 are affected by CVE-2021-28812.
CVE-2021-28812 has a severity score of 8.8 (High).
To fix CVE-2021-28812, it is recommended to update Video Station to version 5.5.4 or later on QTS 4.5.2.