QNAP Security Advisories & CVEs
46 advisories tracked · QNAP PSIRT (security@qnap.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor QNAP CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your QNAP device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in QNAP's recent advisories.
Official source
QNAP PSIRT (security@qnap.com CNA) via NVD
QNAP is its own CVE Numbering Authority. VulniPulse ingests QNAP's CVEs from the NVD CNA feed (security@qnap.com), grouped by their official QSA advisory, and enriches each from the security-advisory page — the vendor's severity, affected apps/OS and the fixed build. Covers QTS, QuTS hero and QuTScloud (NAS operating systems), plus QVR, Qsync, HBS 3, Netatalk, Malware Remover, License Center and Photo/Video/Music Station — QNAP NAS are a relentless ransomware target (DeadBolt, Qlocker), so an alert-hungry community.
Latest QNAP advisories
Critical [CVE-2019-7195] Photo Station: This external control of file name or path vulnerability allows remote attackers to access or modify system files.
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Critical [CVE-2019-7193] QTS: This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system.
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
Critical [CVE-2019-7192] Photo Station: This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
Critical [CVE-2019-7183] QTS: This improper link resolution vulnerability allows remote attackers to access system files.
This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.
Critical [CVE-2018-0730] QTS: This command injection vulnerability in File Station allows attackers to execute commands on the affected device.
This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
Critical [CVE-2018-0729] Music Station: This command injection vulnerability in Music Station allows attackers to execute commands on the affected device.
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.