CVE-2020-2506 | improper access control vulnerability in Helpdesk
Exp
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.
Conclusion & alert: CVE-2020-2506 is rated Active Exploitation (76.5/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.98%).Core evidence: CISA KEV confirms active exploitation (added 2022-03-25) affecting QNAP Systems / Helpdesk. a weakness (CWE-284) Unauthenticated remote administrative access may be possible.Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Required action: Apply updates per vendor instructions.
Exploit prediction scoring system (EPSS) score for CVE-2020-2506
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).