Evidence dossier

CVE-2020-2509

Command Injection Vulnerability in QTS and QuTS hero

Exploited in the wild (CISA KEV since Apr 11, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 33.4% exploit likelihood as of Aug 27, 2026.

79.681.8Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later

State
PUBLISHED
Published
Apr 17, 2021
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    qnap

    Record text: Command Injection Vulnerability in QTS and QuTS hero

    Inspect raw assertion
    Field
    container
    Value
    Command Injection Vulnerability in QTS and QuTS hero
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 33.38% probability · 98.25th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.333810000000; percentile 0.982480000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Apr 11, 2022 · first observed Jul 19, 2026

Exploit likelihood33.38%

FIRST EPSS · score date Aug 27, 2026 · 98.2th percentile · first observed Aug 27, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
qnapOriginal assertion
Record text

Command Injection Vulnerability in QTS and QuTS hero

Inspect raw assertion
Field
container
Value
Command Injection Vulnerability in QTS and QuTS hero
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

33.38% probability · 98.25th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.333810000000; percentile 0.982480000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
86Underlying assertions
2Canonical products
86Target assertions
0Constraint assertions

Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

4 scope groups

qnap · source assertedQNAP Systems Inc.QTSDirect source scope
Affected: unspecified to before 4.5.2.1566 Build 20210202 (custom comparison)Affected: unspecified to before 4.5.1.1495 Build 20201123 (custom comparison)Affected: unspecified to before 4.3.6.1620 Build 20210322 (custom comparison)Affected: unspecified to before 4.3.4.1632 Build 20210324 (custom comparison)Affected: unspecified to before 4.3.3.1624 Build 20210416 (custom comparison)Affected: unspecified to before 4.2.6 Build 20210327 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "unspecified", "lessThan": "4.5.2.1566 Build 20210202", "versionType": "custom"}, {"status": "affected", "version": "unspecified", "lessThan": "4.5.1.1495 Build 20201123", "versionType": "custom"}, {"status": "affected", "version": "unspecified", "lessThan": "4.3.6.1620 Build 20210322", "versionType": "custom"}, {"status": "affected", "version": "unspecified", "lessThan": "4.3.4.1632 Build 20210324", "versionType": "custom"}, {"status": "affected", "version": "unspecified", "lessThan": "4.3.3.1624 Build 20210416", "versionType": "custom"}, {"status": "affected", "version": "unspecified", "lessThan": "4.2.6 Build 20210327", "versionType": "custom"}]
qnap · source assertedQNAP Systems Inc.QuTS heroDirect source scope
Affected: unspecified to before h4.5.1.1491 build 20201119 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "unspecified", "lessThan": "h4.5.1.1491 build 20201119", "versionType": "custom"}]
NVD CPE · OPERATING SYSTEMqnapqtsVulnerable target · 83 assertions
Any version (unconstrained) (< 4.2.6); Any version (unconstrained) (>= 4.3.5, < 4.3.6); Any version (unconstrained) (>= 4.4.0, < 4.5.1); Version 4.2.6; Version 4.3.3.0174; Version 4.3.3.0868; Version 4.3.3.0998; Version 4.3.3.1051; Version 4.3.3.1098; Version 4.3.3.1161; Version 4.3.3.1252; Version 4.3.3.1315; Version 4.3.3.1386; Version 4.3.3.1432; Version 4.3.4.0358; Version 4.3.4.0370; Version 4.3.4.0372; Version 4.3.4.0374; Version 4.3.4.0387; Version 4.3.4.0411; Version 4.3.4.0416; Version 4.3.4.0427; Version 4.3.4.0434; Version 4.3.4.0435; Version 4.3.4.0451; Version 4.3.4.0483; Version 4.3.4.0486; Version 4.3.4.0506; Version 4.3.4.0516; Version 4.3.4.0526; Version 4.3.4.0551; Version 4.3.4.0557; Version 4.3.4.0561; Version 4.3.4.0569; Version 4.3.4.0593; Version 4.3.4.0597; Version 4.3.4.0604; Version 4.3.4.0899; Version 4.3.4.1029; Version 4.3.4.1082; Version 4.3.4.1190; Version 4.3.4.1282; Version 4.3.4.1368; Version 4.3.4.1417; Version 4.3.4.1463; Version 4.3.6; Version 4.3.6.0895; Version 4.3.6.0907; Version 4.3.6.0923; Version 4.3.6.0944; Version 4.3.6.0959; Version 4.3.6.0979; Version 4.3.6.0993; Version 4.3.6.1013; Version 4.3.6.1033; Version 4.3.6.1070; Version 4.3.6.1154; Version 4.3.6.1218; Version 4.3.6.1263; Version 4.3.6.1286; Version 4.3.6.1333; Version 4.3.6.1411; Version 4.3.6.1446; Version 4.5.1; Version 4.5.1.1456; Version 4.5.1.1461; Version 4.5.1.1465; Version 4.5.1.1480; Version 4.5.2Canonical identity product-81578b5d517b13c57b34c6184dee501c7b2e69f5d366148b8e0d95265e548fc9Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:qnap:qts:4.3.4.0551:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3230ef50-b2cc-4a4d-b353-7be461bb235d
  2. cpe:2.3:o:qnap:qts:4.3.4.0411:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d339c9ba-e6da-4116-b6e0-1c25f047fffd
  3. cpe:2.3:o:qnap:qts:4.3.4.1463:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 58
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2cb16cbc-b3e1-43b1-91c7-0c183df01b2f
  4. cpe:2.3:o:qnap:qts:4.3.4.0434:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    55b35e45-d2b2-45d0-a018-002e5caceb26
  5. cpe:2.3:o:qnap:qts:4.3.4.1417:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 57
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    eb92648c-7555-44b7-b35a-f1f1089b4740
  6. cpe:2.3:o:qnap:qts:4.2.6:build_20191107:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f6259c86-ffda-40e8-af0c-33cc8c108dc9
  7. cpe:2.3:o:qnap:qts:4.2.6:build_20200421:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1d1e5368-9587-4e0a-bb65-d88069ca8490
  8. cpe:2.3:o:qnap:qts:4.3.4.0593:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 48
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9bd98ec7-c26e-4aab-ac6c-56a82c8c2432
  9. cpe:2.3:o:qnap:qts:4.3.4.0483:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f556c8a6-8595-4207-93bf-2b1e8eeb2196
  10. cpe:2.3:o:qnap:qts:4.3.4.0486:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2f10a372-65bb-4fd6-940e-671022385757
  11. cpe:2.3:o:qnap:qts:4.3.4.1190:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 54
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cd0b2ae2-22d3-4e7a-9f0b-85e8db82c632
  12. cpe:2.3:o:qnap:qts:4.3.6.1446:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 76
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e4a24254-768f-4538-9dd8-26dcdeecf7cf
  13. cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 4.2.6
    Match ID
    3777f6cc-9189-4bc0-b336-62ba1efb91a7
  14. cpe:2.3:o:qnap:qts:4.5.1.1465:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 80
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7fe2d3bd-2743-47e3-96e2-7c7c75439946
  15. cpe:2.3:o:qnap:qts:4.3.4.0557:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0dc8b14b-3882-44c4-9ce8-c5d6fc0be00a
  16. cpe:2.3:o:qnap:qts:4.3.4.0569:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 47
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    945ae50d-8745-42b2-9b89-04b21c98657b
  17. cpe:2.3:o:qnap:qts:4.3.4.0387:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b29246b7-aa5b-4bb2-b096-6b2798420fc8
  18. cpe:2.3:o:qnap:qts:4.2.6:build_20170517:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8f523e9f-d101-4c29-a624-74e1f3f8cb7d
  19. cpe:2.3:o:qnap:qts:4.3.4.0358:beta1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d560b30d-6a9f-4a44-b83b-4fab02a94830
  20. cpe:2.3:o:qnap:qts:4.3.4.1082:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 53
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c1af22ba-1772-4bfc-8bc1-3d626e14288f
  21. cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 4.3.5; through excluding 4.3.6
    Match ID
    5e4ce6d6-f834-4b65-adf9-e83c31270788
  22. cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 4.4.0; through excluding 4.5.1
    Match ID
    70a079a5-d3a6-408a-830e-4b5f3ba07efa
  23. cpe:2.3:o:qnap:qts:4.3.3.0998:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    77ffa90f-fdfa-4b73-960f-bee7a92db6ba
  24. cpe:2.3:o:qnap:qts:4.3.4.0597:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 49
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1fdbae33-d3a8-46c7-8c4e-cb0c12ed08b0
  25. cpe:2.3:o:qnap:qts:4.3.4.0358:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e1598eb2-e1b4-472f-909f-2c47618ee884
  26. cpe:2.3:o:qnap:qts:4.2.6:build_20200821:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    886a71d1-9615-47a5-b3c2-cbc6f02961a4
  27. cpe:2.3:o:qnap:qts:4.3.4.0374:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    46505b7d-7cf7-4ef0-b52e-18531bf33675
  28. cpe:2.3:o:qnap:qts:4.3.3.1315:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c8d69e0d-84c1-4988-9d73-2d3f511748d0
  29. cpe:2.3:o:qnap:qts:4.3.4.0427:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e7bcbb16-eaaa-4184-b94c-3e2354bb4d50
  30. cpe:2.3:o:qnap:qts:4.5.2:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 82
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d430fffe-eec5-4ca5-a70f-002f33019cda
  31. cpe:2.3:o:qnap:qts:4.5.1.1456:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 78
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    00084d65-d5b3-4554-aa27-5b4a488845c9
  32. cpe:2.3:o:qnap:qts:4.3.6.0993:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 66
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    caa72d06-4fe1-4dc3-a96b-2975a4a9af84
  33. cpe:2.3:o:qnap:qts:4.3.6.0979:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 65
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b6023a8c-77a8-4b79-acc6-872e98ca0d29
  34. cpe:2.3:o:qnap:qts:4.3.6.1333:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 74
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4eb3e4b8-cf05-4ee2-a0dd-53fd50145893
  35. cpe:2.3:o:qnap:qts:4.3.6.1013:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 67
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0cd59bcf-e119-4910-90ce-dca212d146f5
  36. cpe:2.3:o:qnap:qts:4.3.4.0387:beta2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dea6af09-bcb3-45ee-a59f-5a6cefe8cbac
  37. cpe:2.3:o:qnap:qts:4.3.4.1368:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 56
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ab49b315-b381-47cd-ab70-a5d1dc7649e6
  38. cpe:2.3:o:qnap:qts:4.3.3.1386:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6f583384-38b8-4bb8-a957-bc6dbc145aee
  39. cpe:2.3:o:qnap:qts:4.3.4.0372:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0b2d3d89-414e-46aa-8b02-b5fe969508d3
  40. cpe:2.3:o:qnap:qts:4.3.3.1051:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    491e9ea6-45fc-4d65-9c4e-ab62095dc861
  41. cpe:2.3:o:qnap:qts:4.3.3.0174:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db10f6c0-7cb4-49d2-a1f7-9f3387cd1271
  42. cpe:2.3:o:qnap:qts:4.3.4.0506:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    df9514b2-c366-418e-9659-8501abd6e367
  43. cpe:2.3:o:qnap:qts:4.3.4.1282:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 55
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    483fe324-d554-4f10-b6a6-f2c7818ffb83
  44. cpe:2.3:o:qnap:qts:4.3.3.0868:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1931a1d6-c1e6-410a-9f9e-9fd949d42c58
  45. cpe:2.3:o:qnap:qts:4.3.4.0435:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f7dfa308-8071-4f4e-9457-2bbdf455d861
  46. cpe:2.3:o:qnap:qts:4.3.4.0561:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 46
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d30204b8-097b-42eb-a7ec-9142f7d41eb0
  47. cpe:2.3:o:qnap:qts:4.3.4.1029:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 52
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    485af3dc-126d-464c-a6ed-59746031bcc5
  48. cpe:2.3:o:qnap:qts:4.3.6.1411:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 75
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    45c0adaf-c42e-44ec-96b9-a8ea33aab67d
  49. cpe:2.3:o:qnap:qts:4.3.4.0899:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 51
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    98dcb45e-6024-4bb6-a40a-1cb871343930
  50. cpe:2.3:o:qnap:qts:4.2.6:build_20190730:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cf3c4461-c1b6-43a1-ba5e-d6658efd06ee
  51. cpe:2.3:o:qnap:qts:4.3.6.0895:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 60
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a1ab2488-4d3d-494b-9c93-1aa3c7964644
  52. cpe:2.3:o:qnap:qts:4.3.6.1218:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 71
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4cc2fd13-427c-465c-a829-44224537b6d8
  53. cpe:2.3:o:qnap:qts:4.3.6.0907:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 61
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6c24d008-d055-4a2c-88d4-85fb6dc45efe
  54. cpe:2.3:o:qnap:qts:4.2.6:build_20190322:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1388dbe0-f6bb-44ab-81ac-bfb4e70be820
  55. cpe:2.3:o:qnap:qts:4.2.6:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2d3b1e3a-c9e9-4bb8-8bfc-ae1258722f85
  56. cpe:2.3:o:qnap:qts:4.3.4.0526:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2bcca5a5-c789-42fe-8652-f03618f095be
  57. cpe:2.3:o:qnap:qts:4.3.4.0370:beta1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    acb33269-7f69-45da-9cf0-b0322ffc577d
  58. cpe:2.3:o:qnap:qts:4.5.1:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 77
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    58596171-5a5e-4295-a987-db29944f5877
  59. cpe:2.3:o:qnap:qts:4.3.3.1252:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dc246e80-7a88-4d91-989b-2922c70b1378
  60. cpe:2.3:o:qnap:qts:4.3.3.1098:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    264b823b-e086-464e-a740-68bfb0ab8650
  61. cpe:2.3:o:qnap:qts:4.2.6:build_20200109:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9e01e157-bdf1-4b00-ba9b-6887c0c7dff2
  62. cpe:2.3:o:qnap:qts:4.3.6.1033:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 68
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e8f01168-a599-480d-beb1-fa0195b696e6
  63. cpe:2.3:o:qnap:qts:4.2.6:build_20190921:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a1f11848-6fed-4d58-a177-36d280c0347c
  64. cpe:2.3:o:qnap:qts:4.3.6.1263:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 72
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    15182d24-932e-4cc1-a791-ddfcf8b88c49
  65. cpe:2.3:o:qnap:qts:4.3.4.0516:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    995f09c6-d7c2-493d-815e-e837b371e2e5
  66. cpe:2.3:o:qnap:qts:4.3.6.1070:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 69
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    732218c9-0dd1-4153-bbc4-f9b8dde03456
  67. cpe:2.3:o:qnap:qts:4.3.3.1432:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d7d05b71-caf6-416f-bf92-ab4934474f26
  68. cpe:2.3:o:qnap:qts:4.3.6.0923:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 62
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b64d1a6d-d306-46b8-b345-3d9c38544761
  69. cpe:2.3:o:qnap:qts:4.3.4.0451:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    94f95c29-9ab4-4204-831b-075413055289
  70. cpe:2.3:o:qnap:qts:4.3.4.0374:beta1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d8b39fe2-79a9-478c-ae83-8d9664a6d1f8
  71. cpe:2.3:o:qnap:qts:4.3.4.0604:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 50
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a99818fc-0bc5-45a9-ad55-c02fc0ab1959
  72. cpe:2.3:o:qnap:qts:4.2.6:build_20200611:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b63ce419-871c-4866-8ab1-4bb6461e1d74
  73. cpe:2.3:o:qnap:qts:4.3.6.1154:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 70
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fee80d8e-69f2-4aeb-85e1-1b4e64234a45
  74. cpe:2.3:o:qnap:qts:4.5.1.1461:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 79
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a06ff7a8-3932-489b-b2a5-d6e56220a806
  75. cpe:2.3:o:qnap:qts:4.3.6.0959:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 64
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4bae62e0-5fa0-4b9f-acca-9c8c70ac1f2c
  76. cpe:2.3:o:qnap:qts:4.3.4.0372:beta1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3cabe783-b9ca-4e15-8dc2-75c39f214600
  77. cpe:2.3:o:qnap:qts:4.3.6.0944:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 63
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    067c0a13-525c-4376-a6cc-0b86f7f92670
  78. cpe:2.3:o:qnap:qts:4.5.1.1480:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 81
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    90d78f2b-5951-4b67-bd92-0e82757fd903
  79. cpe:2.3:o:qnap:qts:4.3.4.0370:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a09397c1-338b-499c-bfb5-b758b4ff9617
  80. cpe:2.3:o:qnap:qts:4.3.3.1161:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a5675d7e-1332-445b-be5a-0506e765e99a
  81. cpe:2.3:o:qnap:qts:4.3.6.1286:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 73
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fc7b2f4d-4fb2-4dc2-ae97-c6f3081a9a73
  82. cpe:2.3:o:qnap:qts:4.3.4.0416:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    69859698-f815-489e-a08d-f1e2987c3f7d
  83. cpe:2.3:o:qnap:qts:4.3.6:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 59
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a0e214bd-dc96-4b53-9be7-8dd8f79b4542
NVD CPE · OPERATING SYSTEMqnapquts_heroVulnerable target · 3 assertions
Any version (unconstrained) (< h4.5.1); Version h4.5.1; Version h4.5.1.1472Canonical identity product-0a6983be8c95a10c38b798686f8b7e66f22caa6fe0e778c8bc34c7c367ce8dafLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 83
    Logic
    OR
    Version bounds
    through excluding h4.5.1
    Match ID
    be4f1063-2a90-42a8-95a9-fd3d0fd4618f
  2. cpe:2.3:o:qnap:quts_hero:h4.5.1:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 84
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ca4ba3aa-5273-431b-bcc1-f1caca27af53
  3. cpe:2.3:o:qnap:quts_hero:h4.5.1.1472:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 85
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c9e7923d-8c17-4efe-883b-829215359e3b

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:P/I:P/A:P
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.