CVE-2021-28802

CVE-2021-28802: Command Injection Vulnerabilities in QTS and QuTS hero

Vendor Qnap Systems Inc.
Product QTS
Weakness CWE-78
Published July 1, 2021
Last update September 16, 2024

CVSS base score

What the vulnerability does

01Description

A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions prior to h4.5.1.1582 build 20210217.

Key dates

02Disclosure timeline

July 1, 2021 CVE published
September 16, 2024 Record updated