CVE-2021-34348: Command Injection Vulnerability in QVR
Published Sep 27, 2021
·Updated
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later
Affected Software
1 affected component
QNAP QVR<5.1.5
Remediation
Information
We have already fixed this vulnerability in the following versions of QVR:
QVR 5.1.5 build 20210803 and later
Event History
Sep 27, 2021
CVE Published
via MITRE·12:45 AM
Data Sourced
via MITRE·12:45 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-34348?
CVE-2021-34348 is a command injection vulnerability discovered in QNAP devices running QVR.
2
How does CVE-2021-34348 impact QNAP devices running QVR?
If exploited, CVE-2021-34348 allows remote attackers to run arbitrary commands on the affected QNAP devices.
3
Which QNAP devices are affected by CVE-2021-34348?
QNAP devices running QVR prior to version 5.1.5 build 20210803 are affected by CVE-2021-34348.
4
How severe is CVE-2021-34348?
CVE-2021-34348 has a severity rating of 9.8, indicating a critical vulnerability.
5
How can I fix CVE-2021-34348?
To fix CVE-2021-34348, update your QVR software to version 5.1.5 build 20210803 or later.