CVE-2020-6627

CRITICAL

Seagate Central NAS STCG2000300 STCG3000300 STCG4000300 - OS Command Injection via mv_backend_launch

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-6627. PoCs published by Ege Balci.

AI-analyzed exploit summary This Metasploit module exploits a broken access control vulnerability in Seagate Central NAS to create an admin user and gain SSH access. It manipulates device state and adds a new user with admin privileges.

Description

The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.

Exploits (1)

exploitdb WORKING POC
by Ege Balci · rubyremotehardware
https://www.exploit-db.com/exploits/51487

This Metasploit module exploits a broken access control vulnerability in Seagate Central NAS to create an admin user and gain SSH access. It manipulates device state and adds a new user with admin privileges.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Seagate Central Storage 2015.0916
No auth needed
Prerequisites: Network access to the target device · SSH service enabled on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.1426
EPSS Percentile 94.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (3)
seagate/stcg2000300_firmware
seagate/stcg3000300_firmware
seagate/stcg4000300_firmware
Published Dec 06, 2022
Tracked Since Feb 18, 2026