← back
CVE-2020-36198mediumobserved exploitationCWE-77CWE-78

Command Injection Vulnerability in Malware Remover

35Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendcvss 6.7epss 1.1%
from disclosure to weapon
Published on NVDMay 13
VulnCheck+315d
exploitation probability
1.1%top 35% of all CVEs
observed exploitation
yesVulnCheck
A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue does not affect: QNAP Systems Inc. Malware Remover 3.x.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H