ZSPACE Q2C NAS Command Injection Vulnerability in HTTP POST Request Handler
Vulnerability
A command injection vulnerability has been identified in ZSPACE Q2C NAS devices running firmware versions through 1.1.0210050. The issue arises in the HTTP POST request handler, specifically within the 'zfilev2_api.OpenSafe' function. The vulnerability allows remote attackers to inject and execute arbitrary commands on the affected device by manipulating the 'safe_dir' argument in requests to the '/v2/file/safe/open' endpoint. Exploitation of this vulnerability grants root privileges on the device, allowing complete control over the NAS.
Impact
Exploitation of this vulnerability allows for remote command execution on the affected ZSPACE Q2C NAS device, with the executed commands being run with root privileges. This full administrative access enables an attacker to take complete control of the device.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
