安全ID : QSA-21-51

Command Injection Vulnerability in QVR


  • 发布日期 : November 26, 2021

  • 通用漏洞披露 : CVE-2021-38685

  • 受影响产品: QNAP VS Series NVR

严重程度

严重

状态

已解决


Summary

A command injection vulnerability has been reported to affect QNAP VS Series NVR running QVR. If exploited, this vulnerability allows remote attackers to run arbitrary commands.

We have already fixed the vulnerability in the following versions of QVR:

  • QVR 5.1.6 build 20211109 and later

Recommendation

To secure your device, we strongly recommend updating your system to the latest version to benefit from vulnerability fixes.

Updating QVR

  1. Log on to QVR as administrator.
  2. Go to Control Panel > System Settings > Firmware Update.
  3. Select the Firmware Update tab.
  4. Click Browse... to upload the latest firmware file.
    Tip: Download the latest firmware file for your specific device from https://www.qnapsecurity.com/n/en/product_x_down/.
  5. Click Update System.
    QVR installs the update.

致谢: JPCERT/CC and 00One, Inc.

修订历史:
V1.0 (November 26, 2021) - Published
V1.1 (December 20, 2021) - Modify Acknowledge as JPCERT/CC and 00One, Inc.

选择规格

      显示更多 隐藏更多
      open menu
      back to top