Command Injection Vulnerability in ZSPACE Q2C NAS by ZSPACE
CVE-2025-14106
Key Information:
Badges
What is CVE-2025-14106?
A command injection vulnerability exists in the zfilev2_api.CloseSafe function of the ZSPACE Q2C NAS, specifically within the HTTP POST Request Handler's close endpoint. By manipulating the 'safe_dir' argument, attackers can execute arbitrary commands on the system. This vulnerability is exploitable remotely, and publicly available exploit methods have been documented. Notifications regarding this risk were communicated to the vendor without any response detected.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Q2C NAS 1.1.0210050
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
