CVE-2020-25847

HIGH WAF: High
CVSS 8.8 Published: 2020-12-29
CWE-77 CWE-78 CWE-77

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.

WAF Coverage Analysis

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution
OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution
Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
qnapqtsup to 4.5.1.1495
qnapquts_heroup to h4.5.1.1491

References

Back to CVE Database