CVE-2021-34362: Command Injection Vulnerability in Media Streaming Add-on
A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of Media Streaming add-on: QTS 5.0.0: Media Streaming add-on 500.0.0.3 ( 2021/08/20 ) and later QTS 4.5.4: Media Streaming add-on 500.0.0.3 ( 2021/08/20 ) and later QTS 4.3.6: Media Streaming add-on 430.1.8.12 ( 2021/08/20 ) and later QTS 4.3.3: Media Streaming add-on 430.1.8.12 ( 2021/09/29 ) and later QuTS-Hero 5.0.0: Media Streaming add-on 500.0.0.3 ( 2021/08/20 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-34362?
CVE-2021-34362 is a command injection vulnerability that affects QNAP devices running Media Streaming add-on.
How does CVE-2021-34362 impact QNAP devices?
If exploited, CVE-2021-34362 allows remote attackers to run arbitrary commands on affected QNAP devices.
Which versions of Media Streaming add-on are affected by CVE-2021-34362?
Media Streaming add-on versions up to and excluding 500.0.0.3 are affected by CVE-2021-34362.
How can I fix CVE-2021-34362?
To fix CVE-2021-34362, ensure that you have updated Media Streaming add-on version 500.0.0.3 or later.
Where can I find more information about CVE-2021-34362?
You can find more information about CVE-2021-34362 in the QNAP Security Advisory QSA-21-44.