>> All posts

CVE-2020-36195: QNAP NAS SQL injection in Multimedia Console / Media Streaming

The short version: CVE-2020-36195 is an unauthenticated SQL injection in QNAP's Multimedia Console and Media Streaming add-on. A remote attacker can inject queries to obtain application information from an exposed NAS. QNAP patched it in April 2021, just as ransomware crews (Qlocker) were sweeping internet-facing QNAP devices. It isn't in CISA's KEV catalog, but it's an unauthenticated flaw on a device that shouldn't be internet-facing. Steady hands — update and get it off the internet.

At a glance

FactDetail
Our severity takeModerate — unauthenticated data exposure on an exposed NAS (see below)
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS~1.77% · 75.56th percentile (2026-07-17)
In CISA KEV?No — not listed at time of writing
Known exploited?Not confirmed for this CVE; QNAP devices were broadly targeted in the Qlocker ransomware wave in the same window
Vulnerability typeCWE-89 SQL injection → disclosure of application information
Requires authenticated session?No — pre-authentication
AffectedQNAP NAS running Multimedia Console or the Media Streaming add-on (see fixed versions)
Fixed inQTS 4.3.3: Media Streaming add-on 430.1.8.10+ · QTS 4.3.6: Media Streaming add-on 430.1.8.8+ · QTS 4.4.x and later: Multimedia Console 1.3.4+ (also QTS 4.3.3.1624 Build 20210416+ / QTS 4.3.6.1620 Build 20210322+)

What you need to know

Multimedia Console and the Media Streaming add-on are QNAP components for handling media on a NAS. CVE-2020-36195 is an SQL injection caused by insufficient sanitization of user-supplied input: a remote, unauthenticated attacker can inject SQL and obtain application information from the database.

  • How they find it — internet-wide scanning surfaces exposed QNAP NAS and their web components.
  • How they use it — unauthenticated SQL injection to read application data.
  • What it leads to — disclosure of application information; on internet-facing NAS, the broader risk is that these devices are prime ransomware targets, and QNAP patched this flaw days before the Qlocker campaign hit exposed devices.

How serious we see it

Moderate — with an honest note on the score.

NVD scores it 9.8 (Critical). We rate the practical exposure High rather than reflexively Critical: it's unauthenticated and network-reachable, but the described impact is disclosure of application information, and we're not aware of confirmed in-the-wild exploitation of this specific CVE (it isn't in KEV, and its EPSS is low). What keeps it at High is context — it lives on a class of device that is heavily targeted, should not be internet-facing, and was patched right alongside a real ransomware wave. The reassuring part: fixed versions are published, and the strongest control — keeping the NAS off the public internet — is entirely in your hands.

Recommendations

Straight from QNAP's advisory (QSA-21-11):

  1. Update now. Upgrade Multimedia Console, the Media Streaming add-on, and QTS to the fixed versions listed above.
  2. Get the NAS off the internet. Disable router port forwarding and use QNAP's secure remote-access (myQNAPcloud) instead of direct exposure.
  3. Harden accounts and back up. Use strong, unique passwords, and keep snapshots / offline backups given how aggressively NAS devices are targeted.
  4. Confirm your exposure first. Verify whether any QNAP NAS running these components is reachable from the internet.

How BreachRisk sees it

BreachRisk discovers internet-facing QNAP NAS devices from little more than your domain, fingerprints the product and exposed applications, and flags exposure tied to known vulnerabilities like this one — so a forgotten, internet-facing NAS surfaces as a finding you can act on.

That continuous, outside-in view is the point: NAS devices are exactly the kind of asset that gets stood up for convenience and forgotten, and an attacker's-eye view puts the exposed one on your radar before it becomes someone's target.

References

See your cyber risk, proven.