First published: Mon Sep 27 2021(Updated: )
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Qvr | <5.1.5 |
We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-34351.
The title of the vulnerability is 'Command Injection Vulnerability in QNAP QVR'.
The severity of CVE-2021-34351 is critical with a severity value of 9.8.
The QNAP device running QVR software is affected by CVE-2021-34351.
If exploited, this vulnerability could allow remote attackers to run arbitrary commands.
Yes, the vulnerability has been fixed in QVR 5.1.5 build 20210803 and later versions.
You can find more information about CVE-2021-34351 at the following link: [QNAP Security Advisory QSA-21-35](https://www.qnap.com/en/security-advisory/qsa-21-35).