CVE-2021-34351: Command Injection Vulnerability in QVR
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-34351.
What is the title of the vulnerability?
The title of the vulnerability is 'Command Injection Vulnerability in QNAP QVR'.
What is the severity of CVE-2021-34351?
The severity of CVE-2021-34351 is critical with a severity value of 9.8.
Which software is affected by CVE-2021-34351?
The QNAP device running QVR software is affected by CVE-2021-34351.
How can the vulnerability be exploited?
If exploited, this vulnerability could allow remote attackers to run arbitrary commands.
Has the vulnerability been fixed?
Yes, the vulnerability has been fixed in QVR 5.1.5 build 20210803 and later versions.
Where can I find more information about CVE-2021-34351?
You can find more information about CVE-2021-34351 at the following link: [QNAP Security Advisory QSA-21-35](https://www.qnap.com/en/security-advisory/qsa-21-35).