CVE-2020-6627

CRITICAL

Seagate Stcg2000300 Firmware - OS Command Injection

Title source: rule

Description

The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.

Exploits (1)

exploitdb WORKING POC
by Ege Balci · rubyremotehardware
https://www.exploit-db.com/exploits/51487

Scores

CVSS v3 9.8
EPSS 0.1406
EPSS Percentile 94.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (3)
seagate/stcg2000300_firmware
seagate/stcg3000300_firmware
seagate/stcg4000300_firmware
Published Dec 06, 2022
Tracked Since Feb 18, 2026