CVE-2020-2509—QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
PUBLISHEDvulnerability record
2022-04-11 · last modified June 21, 2025
Metadata
Vulnerability Name
QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
Description
QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.
Known To Be Used in Ransomware Campaigns?
Action
Apply updates per vendor instructions.