Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Legacy VioStor NVR
Vulnerability Description
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
QNAP Systems QVR 操作系统命令注入漏洞
Vulnerability Description
QNAP Systems QVR是中国威联通科技(QNAP Systems)公司的一个QNAP监控系统控制中心。 QNAP Systems QVR 4.x版本存在操作系统命令注入漏洞。攻击者利用该漏洞通过网络执行命令。
CVSS Information
N/A
Vulnerability Type
N/A