ZeroHour

CVE-2020-2509

KEVmass

Command Injection RCE in QNAP Network-Attached Storage (NAS)

CISA: QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
33%p98
Published
()
KEV added
AI analysis

QNAP Network-Attached Storage (NAS) devices contain a command injection vulnerability (CWE-77/CWE-78) in which unsanitized input is passed to an operating-system command shell, allowing remote attackers to run arbitrary commands. The flaw is reachable over the network through the NAS device's software interfaces, so an attacker who can reach a vulnerable device can trigger the injection and achieve remote code execution. Successful exploitation gives an attacker control of the NAS, including access to stored data and a potential foothold for lateral movement or ransomware, though CISA has not confirmed ransomware use in this case. Any organization running an affected QNAP NAS device is exposed, especially where the management interface is internet-facing; exact affected version ranges are not stated in the available data and should be taken from QNAP's security advisory. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-11, indicating exploitation has been observed in the wild, and its 33.4% EPSS score (98th percentile) signals elevated near-term exploitation risk, although no public PoC is known.

What to do: Apply the vendor's firmware/OS updates per QNAP's security advisory, as this is the required action under CISA's KEV catalog. Until patched, remove direct internet exposure of NAS management interfaces and restrict access via firewall rules or VPN. Because exploitation has been observed in the wild, check NAS logs for unexpected commands, processes, or logins even after updating.

Affected
QNAP Network-Attached Storage (NAS)
Estimated exposure
massHundreds of thousands of internet-exposed QNAP NAS devices (total installed base in the millions of units) — Estimated from QNAP's multi-million-unit NAS installed base combined with public internet scans that regularly index on the order of hundreds of thousands of QNAP NAS management interfaces exposed online.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later

CISA Known Exploited Vulnerability
Affected
QNAP QNAP Network-Attached Storage (NAS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
qnap
Products
qts, quts hero
Weakness
CWE-77, CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news