← back
CVE-2021-28812

Command Injection Vulnerability in Video Station

CVSS 8.8 HIGHEPSS 1.6%CWE-1286CWE-77CWE-78
In short

A flaw in QNAP Video Station allows attackers to run unauthorized commands on affected systems through the application. This can lead to complete system compromise if not patched.

Technical detail

Command injection vulnerability in Video Station (pre-5.5.4) on QTS 4.5.2, QuTS hero h4.5.2, and QuTScloud c4.5.4 enables remote code execution without authentication. The vulnerability stems from insufficient input sanitization in command processing, allowing attackers to inject and execute arbitrary OS commands with application privileges.

Summary generated and translated by AI from the official description.
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2; versions prior to 5.5.4 on QuTS hero h4.5.2; versions prior to 5.5.4 on QuTScloud c4.5.4. This issue does not affect: QNAP Systems Inc. Video Station on QTS 4.3.6; on QTS 4.3.3.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →