First published: Mon Sep 27 2021(Updated: )
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Qvr | <5.1.5 |
We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this command injection vulnerability affecting QNAP devices running QVR is CVE-2021-34349.
The severity of CVE-2021-34349 is high with a CVSS score of 7.2.
CVE-2021-34349 allows remote attackers to run arbitrary commands on QNAP devices running QVR.
The CVE-2021-34349 vulnerability has been fixed in QVR 5.1.5 build 20210803 and later.
More information about CVE-2021-34349 can be found in the QNAP security advisory QSA-21-35.