CVE-2021-32530

CRITICAL

QSAN XEVO < 1.2.0 - Unauthenticated OS Command Injection via Array Status Parameter

Title source: llm
STIX 2.1

Description

OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status parameter. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-4886-d3b14-1.html

Scores

CVSS v3 9.8
EPSS 0.0231
EPSS Percentile 81.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
qsan/xevo < 1.2.0
Published Jul 07, 2021
Tracked Since Feb 18, 2026