Skip to content
VulniPulse

QNAP Security Advisories & CVEs

326 advisories tracked · QNAP PSIRT (security@qnap.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor QNAP CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your QNAP device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in QNAP's recent advisories.

Official source

QNAP PSIRT (security@qnap.com CNA) via NVD

QNAP is its own CVE Numbering Authority. VulniPulse ingests QNAP's CVEs from the NVD CNA feed (security@qnap.com), grouped by their official QSA advisory, and enriches each from the security-advisory page — the vendor's severity, affected apps/OS and the fixed build. Covers QTS, QuTS hero and QuTScloud (NAS operating systems), plus QVR, Qsync, HBS 3, Netatalk, Malware Remover, License Center and Photo/Video/Music Station — QNAP NAS are a relentless ransomware target (DeadBolt, Qlocker), so an alert-hungry community.

Latest QNAP advisories

High8.1QNAP

High [CVE-2021-38687] QTS: stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station.

A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later

CVE-2021-38687
QTS
Dec 29, 2021
Medium5.3QNAP

Medium [CVE-2021-38680] cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server.

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.20 and later

CVE-2021-38680
Unclassified
Dec 29, 2021
Critical9.8QNAP

Critical [CVE-2020-2501] QNAP NAS: stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station.

A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following versions: Surveillance Station 5.1.5.4.3 (and later) for ARM CPU NAS (64bit OS) and x86 CPU NAS (64bit OS) Surveillance Station 5.1.5.3.3 (and later) for ARM CPU NAS (32bit OS) and x86 CPU NAS (32bit OS)

CVE-2020-2501
Unclassified
Feb 17, 2021
Medium6.1QNAP

Medium [CVE-2020-2502] Photo Station: This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code.

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later

CVE-2020-2502
Applications
Feb 17, 2021
Critical9.8QNAP

Critical [CVE-2020-2507] QTS: The vulnerability have been reported to affect earlier versions of QTS.

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.

CVE-2020-2507
QTS
Feb 3, 2021
High7.3QNAP Exploited CISA KEV

High [CVE-2020-2506] QTS: The vulnerability have been reported to affect earlier versions of QTS.

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.

CVE-2020-2506
QTS
Feb 3, 2021
High7.2QNAP

High [CVE-2020-2508] QTS: command injection vulnerability has been reported to affect QTS and QuTS hero.

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later)

CVE-2020-2508
QTSQuTS hero
Jan 11, 2021
Critical9.1QNAP

Critical [CVE-2018-19945] QTS: vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6.

A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. QNAP have already fixed this vulnerability in the following versions: QTS 4.3.6.0895 build 20190328 (and later) QTS 4.3.4.0899 build 20190322 (and later) This issue does not affect QTS 4.4.x or QTS 4.5.x.

CVE-2018-19945
QTS
Dec 31, 2020
High7.5QNAP

High [CVE-2018-19944] QTS: cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices.

A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerability in the following versions: QTS 4.4.3.1354 build 20200702 (and later)

CVE-2018-19944
QTS
Dec 31, 2020
High7.5QNAP

High [CVE-2018-19941] QTS: vulnerability has been reported to affect QNAP NAS.

A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later) QuTScloud c4.5.2.1379 build 20200730 (and later)

CVE-2018-19941
QTSQuTS hero
Dec 31, 2020
Critical9.0QNAP

Critical [CVE-2020-2503] If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station

If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

CVE-2020-2503
Unclassified
Dec 24, 2020
Medium5.8QNAP

Medium [CVE-2020-2504] If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station.

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

CVE-2020-2504
Unclassified
Dec 24, 2020
Medium6.3QNAP

Medium [CVE-2020-2499] hard-coded password vulnerability has been reported to affect earlier versions of QES.

A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.

CVE-2020-2499
Unclassified
Dec 24, 2020
Low2.3QNAP

Low [CVE-2020-2505] If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages.

If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

CVE-2020-2505
Unclassified
Dec 24, 2020
Critical9.8QNAP

Critical [CVE-2019-7198] QTS: This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application.

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later

CVE-2019-7198
QTSQuTS hero
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2498] QTS: If exploited, this cross-site scripting vulnerability could

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later

CVE-2020-2498
QTSQuTS hero
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2497] QTS: If exploited, this cross-site scripting vulnerability could

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later

CVE-2020-2497
QTSQuTS hero
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2496] QTS: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later

CVE-2020-2496
QTSQuTS hero
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2494] QTS: This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code.

This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12 and later

CVE-2020-2494
QTSQuTS heroApplications
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2493] Multimedia Console: This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code.

This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in Multimedia Console 1.1.5 and later.

CVE-2020-2493
Applications
Dec 10, 2020

← All vendors