
CISA just added CVE-2020-5849 to KEV — a 2020 Unraid auth bypass still being exploited in the wild. Chains with CVE-2020-5847 for full RCE. Five-year-old vulns in NAS boxes are low-hanging fruit for ransomware crews targeting backup infrastructure.
Post summary
CISA has added CVE‑2020‑5849 to the KEV list, noting it is still exploited in the wild and can be chained with CVE‑2020‑5847 for full remote code execution, representing a significant risk for NAS devices.
