Skip to content
VulniPulse

QNAP Security Advisories & CVEs

326 advisories tracked · QNAP PSIRT (security@qnap.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor QNAP CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your QNAP device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in QNAP's recent advisories.

Official source

QNAP PSIRT (security@qnap.com CNA) via NVD

QNAP is its own CVE Numbering Authority. VulniPulse ingests QNAP's CVEs from the NVD CNA feed (security@qnap.com), grouped by their official QSA advisory, and enriches each from the security-advisory page — the vendor's severity, affected apps/OS and the fixed build. Covers QTS, QuTS hero and QuTScloud (NAS operating systems), plus QVR, Qsync, HBS 3, Netatalk, Malware Remover, License Center and Photo/Video/Music Station — QNAP NAS are a relentless ransomware target (DeadBolt, Qlocker), so an alert-hungry community.

Latest QNAP advisories

Medium4.9QNAP

Medium [CVE-2025-52866] QTS: NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later Affected products named by the advisory: QTS 5.2.x; QuTS hero h5.2.x.

CVE-2025-52866
QTSQuTS hero
Oct 3, 2025
Medium4.9QNAP

Medium [CVE-2025-52432] QTS: NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.3.0.3192 build 20250716 and later Affected products named by the advisory: QTS 5.2.x; QuTS hero h5.2.x.

CVE-2025-52432
QTSQuTS hero
Oct 3, 2025
Medium4.9QNAP

Medium [CVE-2025-47211] QTS: path traversal vulnerability has been reported to affect several QNAP operating system versions.

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later Affected products named by the advisory: QTS 5.2.x; QuTS hero h5.2.x.

CVE-2025-47211
QTSQuTS hero
Oct 3, 2025
Medium6.5QNAP

Medium [CVE-2025-47210] Qsync: NULL pointer dereference vulnerability has been reported to affect Qsync Central.

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.2 ( 2025/07/31 ) and later

CVE-2025-47210
Applications
Oct 3, 2025
Medium6.5QNAP

Medium [CVE-2025-44012] Qsync: allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central.

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.2 ( 2025/07/31 ) and later

CVE-2025-44012
Applications
Oct 3, 2025
Medium6.5QNAP

Medium [CVE-2025-44011] Qsync: NULL pointer dereference vulnerability has been reported to affect Qsync Central.

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later

CVE-2025-44011
Applications
Oct 3, 2025
Medium6.5QNAP

Medium [CVE-2025-44007] Qsync: allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central.

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later

CVE-2025-44007
Applications
Oct 3, 2025
Medium6.5QNAP

Medium [CVE-2025-33034] Qsync: path traversal vulnerability has been reported to affect Qsync Central.

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later

CVE-2025-33034
Applications
Oct 3, 2025
Critical9.8QNAP

Critical [CVE-2025-52856] improper authentication vulnerability has been reported to affect VioStor.

An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621 and later

CVE-2025-52856
Unclassified
Aug 29, 2025
High8.4QNAP

High [CVE-2025-44015] command injection vulnerability has been reported to affect HybridDesk Station.

A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: HybridDesk Station 4.2.18 and later

CVE-2025-44015
Unclassified
Aug 29, 2025
High8.8QNAP

High [CVE-2025-30278] Qsync: improper certificate validation vulnerability has been reported to affect Qsync Central.

An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

CVE-2025-30278
Applications
Aug 29, 2025
High8.1QNAP

High [CVE-2025-30273] QTS: out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions.

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

CVE-2025-30273
QTSQuTS hero
Aug 29, 2025
High8.8QNAP

High [CVE-2025-30264] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

CVE-2025-30264
QTSQuTS hero
Aug 29, 2025
High8.8QNAP

High [CVE-2025-29894] Qsync: SQL injection vulnerability has been reported to affect Qsync Central.

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

CVE-2025-29894
Applications
Aug 29, 2025
High7.2QNAP

High [CVE-2025-29887] command injection vulnerability has been reported to affect QuRouter 2.5.1.

A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.5.1.060 and later

CVE-2025-29887
Unclassified
Aug 29, 2025
Medium6.5QNAP

Medium [CVE-2025-33038] Qsync: path traversal vulnerability has been reported to affect Qsync Central.

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

CVE-2025-33038
Applications
Aug 29, 2025
Medium4.9QNAP

Medium [CVE-2025-33032] QTS: path traversal vulnerability has been reported to affect several QNAP operating system versions.

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

CVE-2025-33032
QTSQuTS hero
Aug 29, 2025
Medium6.5QNAP

Medium [CVE-2025-30275] Qsync: NULL pointer dereference vulnerability has been reported to affect Qsync Central.

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

CVE-2025-30275
Applications
Aug 29, 2025
Medium6.5QNAP

Medium [CVE-2025-30274] QTS: NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

CVE-2025-30274
QTSQuTS hero
Aug 29, 2025
Medium6.5QNAP

Medium [CVE-2025-30271] QTS: path traversal vulnerability has been reported to affect several QNAP operating system versions.

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

CVE-2025-30271
QTSQuTS hero
Aug 29, 2025

← All vendors