First published: Mon Sep 27 2021(Updated: )
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Qvr | <5.1.5 |
We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34348 is a command injection vulnerability discovered in QNAP devices running QVR.
If exploited, CVE-2021-34348 allows remote attackers to run arbitrary commands on the affected QNAP devices.
QNAP devices running QVR prior to version 5.1.5 build 20210803 are affected by CVE-2021-34348.
CVE-2021-34348 has a severity rating of 9.8, indicating a critical vulnerability.
To fix CVE-2021-34348, update your QVR software to version 5.1.5 build 20210803 or later.