← Back

CVE-2024-48861

nvd nist
Published: Nov 22, 2024Modified: Sep 24, 2025

JSON object

Loading...
7.3
Vector
CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@qnapsecurity.com.tw (Secondary)

Description

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and later

Affected (6)

Products: Qnap: Qurouter
1 product
Qurouter
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 2.4.0.190 build_20240522
Version 2.4.1.172 build_20240606
Version 2.4.1.634 build_20240710
Version 2.4.2.317 build_20240903
Version 2.4.2.538 build_20240923
Version 2.4.3.103 build_20241011

References (1)

Source: security@qnapsecurity.com.tw
Vendor Advisory

Timeline

No history available yet.