CVE-2020-2504: QNAP Qes

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

Affected products

  • QNAP Qes: before 2.1.1 (fixed in 2.1.1); version 2.1.1 only

Published 2020-12-24. Last modified 2026-06-17.