CVE-2021-47816
HIGH 8.8EPSS 1.7%
Thecus N4800Eco NAS Server Control Panel contains a command injection vulnerability that allows authenticated attackers to execute arbitrary system commands through user management endpoints. Attackers can inject commands via username and batch user creation parameters to execute shell commands with administrative privileges.
- CVSS v4.0
- 5.3 MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 1.69% chance of exploitation in the next 30 days, 75th percentile
- Published
- 2026-01-16
- Updated
- 2026-07-28
Proof-of-concept exploits (2)
- https://www.exploit-db.com/exploits/49926
- https://docs.unsafe-inline.com/0day/thecus-n4800eco-nas-server-control-panel-comand-injec…