Thecus N4800Eco NAS Server Control Panel contains a command injection vulnerability that allows authenticated attackers to execute arbitrary system commands through user management endpoints. Attackers can inject commands via username and batch user creation parameters to execute shell commands with administrative privileges.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Thecus N4800Eco NAS Server Control Panel contains a command injection vulnerability that allows authenticated attackers to execute arbitrary system commands through user management endpoints. Attackers can inject commands via username and batch user creation parameters to execute shell commands with administrative privileges. | |
| Title | Thecus N4800Eco Nas Server Control Panel - Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-16T20:43:27.338Z
Reserved: 2026-01-14T17:11:19.895Z
Link: CVE-2021-47816
Updated: 2026-01-16T20:42:38.397Z
Status : Received
Published: 2026-01-16T19:16:06.197
Modified: 2026-01-16T19:16:06.197
Link: CVE-2021-47816
No data.
OpenCVE Enrichment
No data.