VYPR

Q2c Nas Firmware

by Zspace

CVEs (3)

  • CVE-2025-14108HigDec 5, 2025
    risk 0.58cvss 8.8epss 0.10

    A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.OpenSafe of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation of the argument safe_dir causes command injection. It is…

  • CVE-2025-14107HigDec 5, 2025
    risk 0.58cvss 8.8epss 0.12

    A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this vulnerability is the function zfilev2_api.SafeStatus of the file /v2/file/safe/status of the component HTTP POST Request Handler. The manipulation of the argument safe_dir results in…

  • CVE-2025-14106HigDec 5, 2025
    risk 0.58cvss 8.8epss 0.12

    A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of the file /v2/file/safe/close of the component HTTP POST Request Handler. The manipulation of the argument safe_dir leads to command injection. The attack is…