Critical severity9.8NVD Advisory· Published Dec 6, 2022· Updated Jun 17, 2026
CVE-2020-6627
CVE-2020-6627
Description
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:o:seagate:stcg2000300_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:seagate:stcg3000300_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:seagate:stcg4000300_firmware:-:*:*:*:*:*:*:*
- Seagate/Central NASdescription
Patches
Vulnerability mechanics
References
4- github.com/rapid7/metasploit-framework/pull/12844nvdExploitIssue TrackingThird Party Advisory
- pentest.blog/advisory-seagate-central-storage-remote-code-execution/nvdExploitThird Party Advisory
- www.invictuseurope.com/blog/nvdBroken Link
- packetstormsecurity.com/files/172590/Seagate-Central-Storage-2015.0916-User-Creation-Command-Execution.htmlnvd
News mentions
0No linked articles in our index yet.