CVE-2020-25847: QNAP QTS
High severity, CVSS 8.8. EPSS: 2.6% chance of exploitation in the next 30 days.
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.
Affected products
- QNAP QTS: before 4.5.1.1495 (fixed in 4.5.1.1495)
- QNAP Quts Hero: before h4.5.1.1491 (fixed in h4.5.1.1491)
Published 2020-12-29. Last modified 2026-06-17.