VYPR
Critical severity9.8NVD Advisory· Published Nov 26, 2021· Updated Jun 17, 2026

CVE-2021-38685

CVE-2021-38685

Description

A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR FW 5.1.6 build 20211109 and later

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Qnap/QVR2 versions
    cpe:2.3:a:qnap:qvr:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:qnap:qvr:*:*:*:*:*:*:*:*range: <5.1.6
    • (no CPE)range: QVR FW 5.1.6 build 20211109 and later
  • Qnap/VioStorllm-fuzzy
    Range: QVR FW 5.1.6 build 20211109 and later
  • QNAP Systems Inc./QVRv5
    Range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.