High severity8.8NVD Advisory· Published Dec 29, 2020· Updated Jun 17, 2026
CVE-2020-25847
CVE-2020-25847
Description
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- QNAP Systems Inc./QTSv5Range: 4.3.x
- QNAP Systems Inc./QuTS herov5Range: unspecified
Patches
Vulnerability mechanics
References
1- www.qnap.com/en/security-advisory/qsa-20-20nvdVendor Advisory
News mentions
0No linked articles in our index yet.