CVE-2020-2509
악용 확인 QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
악용 여부
악용 확인
2022-04-11
2022-05-02
CISA 미확인
QNAP QNAP Network-Attached Storage (NAS)
심각도 (발행처 발표값)
심각9.8
3.1
NVD (미국 NIST)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
악용 확률 (EPSS)
33.4%
33.38%
98.3%
2026-09-04
한국어 공식 권고
CISA 원문
QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.— CISA KEV · shortDescription 원문
Apply updates per vendor instructions.— CISA KEV · requiredAction 원문
취약점 설명 (NVD 원문)
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later
CWE-77 CWE-78 CWE-77
이 페이지는 조치 지시가 아닙니다. 영향 범위와 패치 버전은 제품·구성에 따라 다르므로, 반드시 공급사 공식 권고와 NVD 원문의 참조 링크를 확인하세요.