CVE-2020-2509

Confirmed PUBLISHED

Command Injection Vulnerability in QTS and QuTS hero

QNAP Systems Inc. · QTS, QuTS hero
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later

cisa windows
CVE Published
Apr 17, 2021
Exploitation Reported
Apr 11, 2022
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
QNAP Systems Inc.
QTS

unspecified to < 4.5.2.1566 Build 20210202

Affected
QNAP Systems Inc.
QTS

unspecified to < 4.5.1.1495 Build 20201123

Affected
QNAP Systems Inc.
QTS

unspecified to < 4.3.6.1620 Build 20210322

Affected
QNAP Systems Inc.
QTS

unspecified to < 4.3.4.1632 Build 20210324

Affected
QNAP Systems Inc.
QTS

unspecified to < 4.3.3.1624 Build 20210416

Affected
QNAP Systems Inc.
QTS

unspecified to < 4.2.6 Build 20210327

Affected
QNAP Systems Inc.
QuTS hero

unspecified to < h4.5.1.1491 build 20201119

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.