← back
CVE-2021-47816

Thecus N4800Eco Nas Server Control Panel - Command Injection

CVSS 5.3 MEDIUMEPSS 1.6%CWE-78
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 1.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
16 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Thecus N4800Eco NAS Server Control Panel contains a command injection vulnerability that allows authenticated attackers to execute arbitrary system commands through user management endpoints. Attackers can inject commands via username and batch user creation parameters to execute shell commands with administrative privileges.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N