CVE-2020-2492: QNAP QTS

High severity, CVSS 7.2. EPSS: 1.7% chance of exploitation in the next 30 days.

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.

Affected products

  • QNAP QTS: before 4.4.3.1421 (fixed in 4.4.3.1421)

Published 2020-11-16. Last modified 2026-06-17.