Vulnerability record · CVE-2020-6627 · published 6 December 2022
CVE-2020-6627: Seagate stcg2000300 firmware os command injection vulnerability
Seagate · Stcg2000300 Firmware
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.
Description
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/172590/Seagate-Central-Storage-2015.0916-User-Creation-Command-Execution.html | |
| https://github.com/rapid7/metasploit-framework/pull/12844 | ExploitIssue TrackingThird Party Advisory |
| https://pentest.blog/advisory-seagate-central-storage-remote-code-execution/ | ExploitThird Party Advisory |
| https://www.invictuseurope.com/blog/ | Broken Link |
| http://packetstormsecurity.com/files/172590/Seagate-Central-Storage-2015.0916-User-Creation-Command-Execution.html | |
| https://github.com/rapid7/metasploit-framework/pull/12844 | ExploitIssue TrackingThird Party Advisory |
| https://pentest.blog/advisory-seagate-central-storage-remote-code-execution/ | ExploitThird Party Advisory |
| https://www.invictuseurope.com/blog/ | Broken Link |
Track CVE-2020-6627 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-6627), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.