← Vulnerability feed

Vulnerability record · CVE-2020-2509 · published 17 April 2021

CVE-2020-2509: QNAP QTS and QuTS hero command injection

Qnap · Qts

QTS and QuTS hero contain a command injection flaw that lets an attacker run arbitrary commands within a compromised application. It is remotely reachable without authentication or user interaction, so unpatched NAS devices are directly exposed. QNAP has released fixed builds for the affected branches.

9.8 CVSS 3.1 Critical CISA KEV since 11 Apr 2022 EPSS 34% · top 1.7% CWE-77 · Command injectionCWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 7.5
34%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, no authentication or interaction required, and KEV listing with high EPSS make this an actively exploited critical flaw.

What it is

QTS and QuTS hero contain a command injection flaw that lets an attacker run arbitrary commands within a compromised application. It is remotely reachable without authentication or user interaction, so unpatched NAS devices are directly exposed. QNAP has released fixed builds for the affected branches.

Impact

An attacker can execute arbitrary operating system commands on the NAS, leading to full compromise of confidentiality, integrity and availability of the device and its data.

Attack surface

Reached over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not name the specific vulnerable endpoint or service.

Exploitation

CVE-2020-2509 is listed in CISA KEV with a 2022-05-02 remediation due date, and EPSS shows a 30-day probability of 0.33381 (98.3rd percentile), indicating active exploitation is expected. No ransomware campaign use is recorded.

What to do

  • Apply the vendor fixed builds: QTS 4.5.2.1566, 4.5.1.1495, 4.3.6.1620, 4.3.4.1632, 4.3.3.1624, 4.2.6 Build 20210327, or QuTS hero h4.5.1.1491 build 20201119 and later.
  • Remove internet exposure from QTS and QuTS hero management interfaces; restrict access to trusted networks or VPN.
  • Disable or block unused NAS services and remote access features to shrink the reachable attack surface.
  • Monitor QNAP advisories and re-check firmware versions on all deployed NAS units, including branch-office devices.
  • Treat any unpatched, internet-facing QNAP NAS as compromised and review it for unauthorized changes.

Detection

  • Hunt for unexpected child processes spawned by QTS/QuTS web or application services, especially shell interpreters.
  • Review NAS logs and network traffic for anomalous outbound connections or command execution patterns from the device.
  • Audit firmware versions across all QNAP NAS assets to identify units below the fixed builds.
  • Alert on new or modified files, cron entries, or startup scripts on NAS systems that could indicate persistence.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-2509 to the Known Exploited Vulnerabilities catalog on 11 April 2022 as "QNAP Network-Attached Storage (NAS) Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 2 May 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-2509 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-19949QNAP QTS File Station command injection allows remote code executionQNAP QTS contains a command injection flaw in File Station that lets remote attackers run arbitrary commands on the NAS. It is remotely reachable wit…KEVEPSS 28%analysed9.8CVE-2019-7193QNAP QTS improper input validation allows remote code injectionQNAP QTS contains an improper input validation flaw that lets remote attackers inject arbitrary code into the system. It is remotely reachable withou…KEVEPSS 14%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed6.1CVE-2018-19953QNAP QTS File Station cross-site scripting flawQNAP QTS contains a cross-site scripting vulnerability in File Station that lets remote attackers inject malicious code. It matters because the flaw …KEVEPSS 29%analysed5.4CVE-2018-19943QNAP QTS File Station cross-site scriptingQNAP QTS contains a cross-site scripting flaw in File Station that lets a remote attacker inject malicious code. It matters because the vendor has fi…KEVEPSS 21%analysed10.0CVE-2024-32766Qnap qts command injection vulnerabilityAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…EPSS 2.3%10.0CVE-2017-7876Qnap qts command injection vulnerabilityThis command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the is…EPSS 3.3%

Source: NIST National Vulnerability Database (record CVE-2020-2509), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.