CVE-2021-32531

CRITICAL

QSAN XEVO < 2.1.0 - Unauthenticated OS Command Injection in Init Function

Title source: llm
STIX 2.1

Description

OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-4887-ee5e3-1.html

Scores

CVSS v3 9.8
EPSS 0.0206
EPSS Percentile 78.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
qsan/xevo < 2.1.0
Published Jul 07, 2021
Tracked Since Feb 18, 2026