Impact
Command injection allows a remote attacker who has acquired an administrator account to execute arbitrary commands on the affected QNAP devices. The attacker can gain full control over the system, compromising confidentiality, integrity, and potentially availability by terminating services or erasing data.
Affected Systems
Affecting QNAP Systems Inc. QTS and QuTS hero operating systems. Vulnerable versions are all releases prior to QTS 5.2.9.3410 build 20260214, QuTS hero h5.2.9.3410 build 20260214, QuTS hero h5.3.4.3500 build 20260520, and QuTS hero h6.0.0.3397 build 20260206.
Risk and Exploitability
The CVSS score of 8.6 signals a high severity flaw, and although the EPSS score is not available, the vulnerability does not appear in the CISA KEV catalog. The likely attack vector is remote and requires an attacker to first obtain or compromise an administrator account. Once administrative access is achieved, the command injection can be exploited to run arbitrary commands without additional constraints.
OpenCVE Enrichment