← back
CVE-2021-32533criticalCWE-78

QSAN SANOS - Command Injection

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 1.9%
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
nono source reports it
In short

The QSAN SANOS settings page fails to filter user input, allowing attackers to inject and run arbitrary commands on the system. This is critical because it gives complete control of the device to unauthorized users.

Technical detail

CWE-78 command injection via unfiltered parameters in the SANOS settings interface allows unauthenticated remote code execution with no special privileges required (CVSS 9.8). Attack vector exploits insufficient input validation in the web administration panel to achieve system-level command execution.

Summary generated and translated by AI from the official description.
The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN SANOS v2.1.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
QSAN · SANOS