CVE-2020-36198: QNAP Malware Remover

Medium severity, CVSS 6.7. EPSS: 1.1% chance of exploitation in the next 30 days.

A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue does not affect: QNAP Systems Inc. Malware Remover 3.x.

Affected products

  • QNAP Malware Remover: from 4.5.4.0, before 4.6.1.0 (fixed in 4.6.1.0)

Published 2021-05-13. Last modified 2026-06-17.