CVE-2020-2490: QNAP QTS

High severity, CVSS 7.2. EPSS: 2.2% chance of exploitation in the next 30 days.

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.

Affected products

  • QNAP QTS: before 4.4.3.1421 (fixed in 4.4.3.1421)

Published 2020-11-16. Last modified 2026-06-17.