Loading HuntDB...

QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

Added April 11, 2022 Due May 2, 2022 CVE-2020-2509
Overdue QNAP / QNAP Network-Attached Storage (NAS) CWE-77 CWE-78

Description

QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
5 months ago