Vulnerability Intelligence Report
Command Injection Vulnerabilities in QTS and QuTS hero
CVE-2021-28802
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions prior to h4.5.1.1582 build 20210217.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:1.82%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-78 ↗CWE-78 OS Command Injection
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| QNAP Systems Inc. | QTS | unspecified < 4.5.1.1540 build 20210107 (affected) |
| QNAP Systems Inc. | QuTS hero | unspecified < h4.5.1.1582 build 20210217 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.816%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | QNAP Systems, Inc. · Vendor · Taiwan |
| Reserved | 2021-03-18T00:00:00 |
| Published | 2021-07-01T02:00:20 |
| Patch Date | 2021-07-01 |
| Last Updated | 2024-09-16T22:15:54 |
Community Chatter & Buzz