"value":"An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network.\n\nWe have already fixed the vulnerability in the following versions:\n\nQVR Firmware 5.0.0\u00a0and later\n\n"
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
"value":"<p>We have already fixed the vulnerability in the following versions:</p><p><span style=\"background-color: var(--wht);\">QVR Firmware 5.0.0</span><span style=\"background-color: var(--wht);\"> and later</span></p>"
}
],
"value":"We have already fixed the vulnerability in the following versions:\n\nQVR Firmware 5.0.0\u00a0and later\n\n"
}
],
"credits":[
{
"lang":"en",
"value":"Chad Seaman and Larry Cashdollar of Akamai Technologies reported this vulnerability to CISA"