March 25, 2022 · Applied Cybernetics Group
CVE-2020-2506 — QNAP Systems Helpdesk
QNAP Helpdesk Improper Access Control Vulnerability
- Added to KEV
2022-03-25- Federal due date
2022-04-15- Vendor
- QNAP Systems
- Product
- Helpdesk
- EPSS
- 95.3th percentile (score 0.180, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2020-2506
CISA short description
QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.
Required action
Apply updates per vendor instructions.