Critical active threat
CVE-2020-2509 QNAP Network-Attached Storage (NAS) Command Injection
- Actively exploited (CISA KEV)
- Listed on CISA KEV
QNAP Network-Attached Storage (NAS) Command Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.