First published: Fri Oct 01 2021(Updated: )
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210902 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Qvr | <5.1.5 |
We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210902 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34352 is a command injection vulnerability affecting QNAP devices running QVR.
CVE-2021-34352 has a severity rating of 9.8 (Critical).
CVE-2021-34352 allows remote attackers to run arbitrary commands on affected QNAP devices running QVR.
Versions up to and excluding QVR 5.1.5 are affected by CVE-2021-34352.
To fix CVE-2021-34352, update your QVR software to version 5.1.5 build 20210902 or later.