This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.
| Software | From | Fixed in |
|---|---|---|
| qnap / quts_hero | - | h4.5.1.1491 |
| qnap / qts | - | 4.5.1.1495 |