CVE-2021-32529

CRITICAL

QSAN SANOS < 2.0.0 and XEVO < 1.2.0 - Unauthenticated Remote Command Execution

Title source: llm
STIX 2.1

Description

Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-4885-b03c8-1.html

Scores

CVSS v3 9.8
EPSS 0.0226
EPSS Percentile 80.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (2)
qsan/sanos < 2.0.0
qsan/xevo < 1.2.0
Published Jul 07, 2021
Tracked Since Feb 18, 2026