AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-3200

MEDIUM · CVSS 5.9 EPSS 0.40%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-09-21 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-3200
Severity
MEDIUM
CVSS
5.9
EPSS
0.40%

Original NVD Description

The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this variable, deobfuscating the key, and running a cryptsetup luksOpen command.