CVE-2024-48861

EUVD-2024-43182
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands.

We have already fixed the vulnerability in the following versions:
QuRouter 2.4.4.106 and later
Command Injection
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
Affected Products (NVD)
VendorProductVersion
qnapqurouter
2.4.0.190:build_20240522
qnapqurouter
2.4.1.172:build_20240606
qnapqurouter
2.4.1.634:build_20240710
qnapqurouter
2.4.2.317:build_20240903
qnapqurouter
2.4.2.538:build_20240923
qnapqurouter
2.4.3.103:build_20241011
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
qnapqurouter
2.4.0 ≤
𝑥
< 2.4.4.106
ADP