CVE-2021-47816
Thecus N4800Eco Nas Server Control Panel - Command Injection
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 1.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
16 ene 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Thecus N4800Eco NAS Server Control Panel contains a command injection vulnerability that allows authenticated attackers to execute arbitrary system commands through user management endpoints. Attackers can inject commands via username and batch user creation parameters to execute shell commands with administrative privileges.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Productos afectados
Thecus · Thecus N4800Eco Nas Server Control PanelReferencias
https://docs.unsafe-inline.com/0day/thecus-n4800eco-nas-server-control-panel-comand-injectionhttps://www.exploit-db.com/exploits/49926https://www.vulncheck.com/advisories/thecus-neco-nas-server-control-panel-command-injectionhttp://www.thecus.com/http://www.thecus.com/product.php?PROD_ID=83