CVE-2020-2509 | Command Injection Vulnerability in QTS and QuTS hero

Exp

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later

Published: 2021-04-17 Last update: 2025-10-27 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2020-2509 is rated Critical Active Threat (93.6/100): CVSS Critical severity, with high exploitation likelihood (EPSS 34.17%, 98th percentile). Core evidence: CISA KEV confirms active exploitation (added 2022-04-11) affecting QNAP / QNAP Network-Attached Storage (NAS). a weakness (CWE-77) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

CISA KEV Record for CVE-2020-2509

Name: QNAP Network-Attached Storage (NAS) Command Injection Vulnerability · CISA KEV detail

Exploit added: 2022-04-11

Action due: 2022-05-02

Required action: Apply updates per vendor instructions.

Exploit prediction scoring system (EPSS) score for CVE-2020-2509

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 84.37% 34.17% -50.20%
2 2026-06-14 83.96% 84.37% +0.41%
3 2026-03-31 83.96%

Full EPSS history (34 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2020-2509

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 [email protected]
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 134c704f-9b21-4f2e-91b3-4a467353bcc0
7.5 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 6.4 [email protected]

Weakness enumeration for CVE-2020-2509

Affected software / configurations for CVE-2020-2509

Vendor Product Version Raw CPE
qnap qts < 4.2.6 cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
qnap qts >= 4.3.5, < 4.3.6 cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
qnap qts >= 4.4.0, < 4.5.1 cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
qnap qts 4.2.6 cpe:2.3:o:qnap:qts:4.2.6:-:*:*:*:*:*:*
qnap qts 4.2.6 cpe:2.3:o:qnap:qts:4.2.6:build_20170517:*:*:*:*:*:*
qnap qts 4.2.6 cpe:2.3:o:qnap:qts:4.2.6:build_20190322:*:*:*:*:*:*
qnap qts 4.2.6 cpe:2.3:o:qnap:qts:4.2.6:build_20190730:*:*:*:*:*:*
qnap qts 4.2.6 cpe:2.3:o:qnap:qts:4.2.6:build_20190921:*:*:*:*:*:*
qnap qts 4.2.6 cpe:2.3:o:qnap:qts:4.2.6:build_20191107:*:*:*:*:*:*
qnap qts 4.2.6 cpe:2.3:o:qnap:qts:4.2.6:build_20200109:*:*:*:*:*:*
qnap qts 4.2.6 cpe:2.3:o:qnap:qts:4.2.6:build_20200421:*:*:*:*:*:*
qnap qts 4.2.6 cpe:2.3:o:qnap:qts:4.2.6:build_20200611:*:*:*:*:*:*
qnap qts 4.2.6 cpe:2.3:o:qnap:qts:4.2.6:build_20200821:*:*:*:*:*:*
qnap qts 4.3.3.0174 cpe:2.3:o:qnap:qts:4.3.3.0174:*:*:*:*:*:*:*
qnap qts 4.3.3.0868 cpe:2.3:o:qnap:qts:4.3.3.0868:*:*:*:*:*:*:*
qnap qts 4.3.3.0998 cpe:2.3:o:qnap:qts:4.3.3.0998:*:*:*:*:*:*:*
qnap qts 4.3.3.1051 cpe:2.3:o:qnap:qts:4.3.3.1051:*:*:*:*:*:*:*
qnap qts 4.3.3.1098 cpe:2.3:o:qnap:qts:4.3.3.1098:*:*:*:*:*:*:*
qnap qts 4.3.3.1161 cpe:2.3:o:qnap:qts:4.3.3.1161:*:*:*:*:*:*:*
qnap qts 4.3.3.1252 cpe:2.3:o:qnap:qts:4.3.3.1252:*:*:*:*:*:*:*
qnap qts 4.3.3.1315 cpe:2.3:o:qnap:qts:4.3.3.1315:*:*:*:*:*:*:*
qnap qts 4.3.3.1386 cpe:2.3:o:qnap:qts:4.3.3.1386:*:*:*:*:*:*:*
qnap qts 4.3.3.1432 cpe:2.3:o:qnap:qts:4.3.3.1432:*:*:*:*:*:*:*
qnap qts 4.3.4.0358 cpe:2.3:o:qnap:qts:4.3.4.0358:*:*:*:*:*:*:*
qnap qts 4.3.4.0358 cpe:2.3:o:qnap:qts:4.3.4.0358:beta1:*:*:*:*:*:*
qnap qts 4.3.4.0370 cpe:2.3:o:qnap:qts:4.3.4.0370:*:*:*:*:*:*:*
qnap qts 4.3.4.0370 cpe:2.3:o:qnap:qts:4.3.4.0370:beta1:*:*:*:*:*:*
qnap qts 4.3.4.0372 cpe:2.3:o:qnap:qts:4.3.4.0372:*:*:*:*:*:*:*
qnap qts 4.3.4.0372 cpe:2.3:o:qnap:qts:4.3.4.0372:beta1:*:*:*:*:*:*
qnap qts 4.3.4.0374 cpe:2.3:o:qnap:qts:4.3.4.0374:*:*:*:*:*:*:*
qnap qts 4.3.4.0374 cpe:2.3:o:qnap:qts:4.3.4.0374:beta1:*:*:*:*:*:*
qnap qts 4.3.4.0387 cpe:2.3:o:qnap:qts:4.3.4.0387:*:*:*:*:*:*:*
qnap qts 4.3.4.0387 cpe:2.3:o:qnap:qts:4.3.4.0387:beta2:*:*:*:*:*:*
qnap qts 4.3.4.0411 cpe:2.3:o:qnap:qts:4.3.4.0411:*:*:*:*:*:*:*
qnap qts 4.3.4.0416 cpe:2.3:o:qnap:qts:4.3.4.0416:*:*:*:*:*:*:*
qnap qts 4.3.4.0427 cpe:2.3:o:qnap:qts:4.3.4.0427:*:*:*:*:*:*:*
qnap qts 4.3.4.0434 cpe:2.3:o:qnap:qts:4.3.4.0434:*:*:*:*:*:*:*
qnap qts 4.3.4.0435 cpe:2.3:o:qnap:qts:4.3.4.0435:*:*:*:*:*:*:*
qnap qts 4.3.4.0451 cpe:2.3:o:qnap:qts:4.3.4.0451:*:*:*:*:*:*:*
qnap qts 4.3.4.0483 cpe:2.3:o:qnap:qts:4.3.4.0483:*:*:*:*:*:*:*
qnap qts 4.3.4.0486 cpe:2.3:o:qnap:qts:4.3.4.0486:*:*:*:*:*:*:*
qnap qts 4.3.4.0506 cpe:2.3:o:qnap:qts:4.3.4.0506:*:*:*:*:*:*:*
qnap qts 4.3.4.0516 cpe:2.3:o:qnap:qts:4.3.4.0516:*:*:*:*:*:*:*
qnap qts 4.3.4.0526 cpe:2.3:o:qnap:qts:4.3.4.0526:*:*:*:*:*:*:*
qnap qts 4.3.4.0551 cpe:2.3:o:qnap:qts:4.3.4.0551:*:*:*:*:*:*:*
qnap qts 4.3.4.0557 cpe:2.3:o:qnap:qts:4.3.4.0557:*:*:*:*:*:*:*
qnap qts 4.3.4.0561 cpe:2.3:o:qnap:qts:4.3.4.0561:*:*:*:*:*:*:*
qnap qts 4.3.4.0569 cpe:2.3:o:qnap:qts:4.3.4.0569:*:*:*:*:*:*:*
qnap qts 4.3.4.0593 cpe:2.3:o:qnap:qts:4.3.4.0593:*:*:*:*:*:*:*
qnap qts 4.3.4.0597 cpe:2.3:o:qnap:qts:4.3.4.0597:*:*:*:*:*:*:*
qnap qts 4.3.4.0604 cpe:2.3:o:qnap:qts:4.3.4.0604:*:*:*:*:*:*:*
qnap qts 4.3.4.0899 cpe:2.3:o:qnap:qts:4.3.4.0899:*:*:*:*:*:*:*
qnap qts 4.3.4.1029 cpe:2.3:o:qnap:qts:4.3.4.1029:*:*:*:*:*:*:*
qnap qts 4.3.4.1082 cpe:2.3:o:qnap:qts:4.3.4.1082:*:*:*:*:*:*:*
qnap qts 4.3.4.1190 cpe:2.3:o:qnap:qts:4.3.4.1190:*:*:*:*:*:*:*
qnap qts 4.3.4.1282 cpe:2.3:o:qnap:qts:4.3.4.1282:*:*:*:*:*:*:*
qnap qts 4.3.4.1368 cpe:2.3:o:qnap:qts:4.3.4.1368:*:*:*:*:*:*:*
qnap qts 4.3.4.1417 cpe:2.3:o:qnap:qts:4.3.4.1417:*:*:*:*:*:*:*
qnap qts 4.3.4.1463 cpe:2.3:o:qnap:qts:4.3.4.1463:*:*:*:*:*:*:*
qnap qts 4.3.6 cpe:2.3:o:qnap:qts:4.3.6:-:*:*:*:*:*:*
qnap qts 4.3.6.0895 cpe:2.3:o:qnap:qts:4.3.6.0895:*:*:*:*:*:*:*
qnap qts 4.3.6.0907 cpe:2.3:o:qnap:qts:4.3.6.0907:*:*:*:*:*:*:*
qnap qts 4.3.6.0923 cpe:2.3:o:qnap:qts:4.3.6.0923:*:*:*:*:*:*:*
qnap qts 4.3.6.0944 cpe:2.3:o:qnap:qts:4.3.6.0944:*:*:*:*:*:*:*
qnap qts 4.3.6.0959 cpe:2.3:o:qnap:qts:4.3.6.0959:*:*:*:*:*:*:*
qnap qts 4.3.6.0979 cpe:2.3:o:qnap:qts:4.3.6.0979:*:*:*:*:*:*:*
qnap qts 4.3.6.0993 cpe:2.3:o:qnap:qts:4.3.6.0993:*:*:*:*:*:*:*
qnap qts 4.3.6.1013 cpe:2.3:o:qnap:qts:4.3.6.1013:*:*:*:*:*:*:*
qnap qts 4.3.6.1033 cpe:2.3:o:qnap:qts:4.3.6.1033:*:*:*:*:*:*:*
qnap qts 4.3.6.1070 cpe:2.3:o:qnap:qts:4.3.6.1070:*:*:*:*:*:*:*
qnap qts 4.3.6.1154 cpe:2.3:o:qnap:qts:4.3.6.1154:*:*:*:*:*:*:*
qnap qts 4.3.6.1218 cpe:2.3:o:qnap:qts:4.3.6.1218:*:*:*:*:*:*:*
qnap qts 4.3.6.1263 cpe:2.3:o:qnap:qts:4.3.6.1263:*:*:*:*:*:*:*
qnap qts 4.3.6.1286 cpe:2.3:o:qnap:qts:4.3.6.1286:*:*:*:*:*:*:*
qnap qts 4.3.6.1333 cpe:2.3:o:qnap:qts:4.3.6.1333:*:*:*:*:*:*:*
qnap qts 4.3.6.1411 cpe:2.3:o:qnap:qts:4.3.6.1411:*:*:*:*:*:*:*
qnap qts 4.3.6.1446 cpe:2.3:o:qnap:qts:4.3.6.1446:*:*:*:*:*:*:*
qnap qts 4.5.1 cpe:2.3:o:qnap:qts:4.5.1:-:*:*:*:*:*:*
qnap qts 4.5.1.1456 cpe:2.3:o:qnap:qts:4.5.1.1456:*:*:*:*:*:*:*
qnap qts 4.5.1.1461 cpe:2.3:o:qnap:qts:4.5.1.1461:*:*:*:*:*:*:*

References for CVE-2020-2509

cvelogic Threat Intelligence