This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.
Publication date: Tue, 29 Dec 2020 13:15:00 +0000