Описание
A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands.
We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:o:qnap:qurouter:2.4.0.190:build_20240522:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.4.1.172:build_20240606:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.4.1.634:build_20240710:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.4.2.317:build_20240903:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.4.2.538:build_20240923:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.4.3.103:build_20241011:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.4.4.106:build_20241017:*:*:*:*:*:*
EPSS
Процентиль: 61%
0.00414
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-78
CWE-78
Связанные уязвимости
CVSS3: 9.8
github
11 месяцев назад
A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later
EPSS
Процентиль: 61%
0.00414
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-78
CWE-78