ZSPACE Q2C NAS Command Injection Vulnerability in HTTP POST Request Handler

Vulnerability

A command injection vulnerability has been identified in ZSPACE Q2C NAS devices running firmware versions through 1.1.0210050. The issue arises in the HTTP POST request handler, specifically within the 'zfilev2_api.CloseSafe' function. The vulnerability allows remote attackers to manipulate the 'safe_dir' argument, injecting and executing arbitrary commands on the affected device. Exploitation of this vulnerability could lead to unauthorized command execution with root privileges, allowing complete control over the victim's NAS.

Impact

Exploitation of this vulnerability allows for unauthorized remote command execution on the affected device, with root privileges, enabling full control over the NAS.

Added: Dec 5, 2025, 10:19 PM
Updated: Dec 5, 2025, 10:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
1.2
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.