Command Injection Vulnerability in ZSPACE Q2C NAS by ZSPACE
CVE-2025-14106
Key Information:
Badges
What is CVE-2025-14106?
A command injection vulnerability exists in the zfilev2_api.CloseSafe function of the ZSPACE Q2C NAS, specifically within the HTTP POST Request Handler's close endpoint. By manipulating the 'safe_dir' argument, attackers can execute arbitrary commands on the system. This vulnerability is exploitable remotely, and publicly available exploit methods have been documented. Notifications regarding this risk were communicated to the vendor without any response detected.
Affected Version(s)
Q2C NAS 1.1.0210050
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
