Answer in brief
CVE-2020-2509 records a High severity vulnerability in Command Injection Vulnerability in QTS and QuTS hero. The current sources mark it as known exploited. The current feed maps QNAP Systems Inc./QTS (generic), QNAP Systems Inc./QuTS hero (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps QNAP Systems Inc./QTS (generic), QNAP Systems Inc./QuTS hero (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| QNAP Systems Inc./QTSgeneric | >=unspecified <4.5.2.1566 Build 20210202 || >=unspecified <4.5.1.1495 Build 20201123 || >=unspecified <4.3.6.1620 Build 20210322 || >=unspecified <4.3.4.1632 Build 20210324 || >=unspecified <4.3.3.1624 Build 20210416 || >=unspecified <4.2.6 Build 20210327 | 4.5.2.1566 Build 20210202, 4.5.1.1495 Build 20201123, 4.3.6.1620 Build 20210322, 4.3.4.1632 Build 20210324, 4.3.3.1624 Build 20210416, 4.2.6 Build 20210327 |
| QNAP Systems Inc./QuTS herogeneric | >=unspecified <h4.5.1.1491 build 20201119 | h4.5.1.1491 build 20201119 |
Published upstream
Apr 17, 2021
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Apr 11, 2022
Evidence: source:kev:kev:kev:recordA command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2020-2509 records a High severity vulnerability in Command Injection Vulnerability in QTS and QuTS hero. The current sources mark it as known exploited. The current feed maps QNAP Systems Inc./QTS (generic), QNAP Systems Inc./QuTS hero (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps QNAP Systems Inc./QTS (generic), QNAP Systems Inc./QuTS hero (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| QNAP Systems Inc./QTSgeneric | >=unspecified <4.5.2.1566 Build 20210202 || >=unspecified <4.5.1.1495 Build 20201123 || >=unspecified <4.3.6.1620 Build 20210322 || >=unspecified <4.3.4.1632 Build 20210324 || >=unspecified <4.3.3.1624 Build 20210416 || >=unspecified <4.2.6 Build 20210327 | 4.5.2.1566 Build 20210202, 4.5.1.1495 Build 20201123, 4.3.6.1620 Build 20210322, 4.3.4.1632 Build 20210324, 4.3.3.1624 Build 20210416, 4.2.6 Build 20210327 |
| QNAP Systems Inc./QuTS herogeneric | >=unspecified <h4.5.1.1491 build 20201119 | h4.5.1.1491 build 20201119 |
Published upstream
Apr 17, 2021
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Apr 11, 2022
Evidence: source:kev:kev:kev:recordA command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later
Quoted source text, attributed separately from HOL analysis.