Skip to content
VulniPulse

QNAP Security Advisories & CVEs

46 advisories tracked · QNAP PSIRT (security@qnap.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor QNAP CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your QNAP device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in QNAP's recent advisories.

Official source

QNAP PSIRT (security@qnap.com CNA) via NVD

QNAP is its own CVE Numbering Authority. VulniPulse ingests QNAP's CVEs from the NVD CNA feed (security@qnap.com), grouped by their official QSA advisory, and enriches each from the security-advisory page — the vendor's severity, affected apps/OS and the fixed build. Covers QTS, QuTS hero and QuTScloud (NAS operating systems), plus QVR, Qsync, HBS 3, Netatalk, Malware Remover, License Center and Photo/Video/Music Station — QNAP NAS are a relentless ransomware target (DeadBolt, Qlocker), so an alert-hungry community.

Latest QNAP advisories

Critical9.8QNAP Exploited CISA KEV

Critical [CVE-2019-7195] Photo Station: This external control of file name or path vulnerability allows remote attackers to access or modify system files.

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CVE-2019-7195
Applications
Dec 5, 2019
Critical9.8QNAP Exploited CISA KEV

Critical [CVE-2019-7193] QTS: This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system.

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

CVE-2019-7193
QTS
Dec 5, 2019
Critical9.8QNAP Exploited CISA KEV

Critical [CVE-2019-7192] Photo Station: This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

CVE-2019-7192
Applications
Dec 5, 2019
Critical9.8QNAP

Critical [CVE-2019-7183] QTS: This improper link resolution vulnerability allows remote attackers to access system files.

This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.

CVE-2019-7183
QTS
Dec 5, 2019
Critical9.8QNAP

Critical [CVE-2018-0730] QTS: This command injection vulnerability in File Station allows attackers to execute commands on the affected device.

This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

CVE-2018-0730
QTS
Dec 4, 2019
Critical9.8QNAP

Critical [CVE-2018-0729] Music Station: This command injection vulnerability in Music Station allows attackers to execute commands on the affected device.

This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.

CVE-2018-0729
Applications
Dec 4, 2019

← All vendors