关于漏洞的关键信息 Title: SGAI N1211DS NAS v1.0.915 Command Injection Description: - Vulnerability: Unauthorized remote command execution due to command injection. - Affected Software: SGAI Space1 NAS, model N1211DS, firmware v1.0.915. - Attack Vector: Attacker can inject malicious commands via the path field in the NNGX_UPLOAD command interface. - Impact: Gains highest level of control over the NAS device. Source: https://www.notion.so/2b16cf4e528a808eadf8dfbcd054740d User: renguangyue (UID 92629) Submission Date: 11/20/2025 08:18 AM Moderation Date: 12/06/2025 10:02 AM Status: Duplicate VulDB Entry: 354604 [SGAI Space1 NAS N1211DS up to 1.0.915 gsaiagent /cgi-bin/JSONAPI RENAME_FILE/OPERATE_FILE/NNGX_UPLOAD command injection] Points: 0