Vulnerability record · CVE-2020-2509 · published 17 April 2021
CVE-2020-2509: QNAP QTS and QuTS hero command injection
Qnap · Qts
QTS and QuTS hero contain a command injection flaw that lets an attacker run arbitrary commands within a compromised application. It is remotely reachable without authentication or user interaction, so unpatched NAS devices are directly exposed. QNAP has released fixed builds for the affected branches.
Description
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, no authentication or interaction required, and KEV listing with high EPSS make this an actively exploited critical flaw.
What it is
QTS and QuTS hero contain a command injection flaw that lets an attacker run arbitrary commands within a compromised application. It is remotely reachable without authentication or user interaction, so unpatched NAS devices are directly exposed. QNAP has released fixed builds for the affected branches.
Impact
An attacker can execute arbitrary operating system commands on the NAS, leading to full compromise of confidentiality, integrity and availability of the device and its data.
Attack surface
Reached over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not name the specific vulnerable endpoint or service.
Exploitation
CVE-2020-2509 is listed in CISA KEV with a 2022-05-02 remediation due date, and EPSS shows a 30-day probability of 0.33381 (98.3rd percentile), indicating active exploitation is expected. No ransomware campaign use is recorded.
What to do
- Apply the vendor fixed builds: QTS 4.5.2.1566, 4.5.1.1495, 4.3.6.1620, 4.3.4.1632, 4.3.3.1624, 4.2.6 Build 20210327, or QuTS hero h4.5.1.1491 build 20201119 and later.
- Remove internet exposure from QTS and QuTS hero management interfaces; restrict access to trusted networks or VPN.
- Disable or block unused NAS services and remote access features to shrink the reachable attack surface.
- Monitor QNAP advisories and re-check firmware versions on all deployed NAS units, including branch-office devices.
- Treat any unpatched, internet-facing QNAP NAS as compromised and review it for unauthorized changes.
Detection
- Hunt for unexpected child processes spawned by QTS/QuTS web or application services, especially shell interpreters.
- Review NAS logs and network traffic for anomalous outbound connections or command execution patterns from the device.
- Audit firmware versions across all QNAP NAS assets to identify units below the fixed builds.
- Alert on new or modified files, cron entries, or startup scripts on NAS systems that could indicate persistence.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-2509 to the Known Exploited Vulnerabilities catalog on 11 April 2022 as "QNAP Network-Attached Storage (NAS) Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 2 May 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-21-05 | Vendor Advisory |
| https://www.qnap.com/en/security-advisory/qsa-21-05 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-2509 | US Government Resource |
Track CVE-2020-2509 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-2509), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.