Skip to content
VulniPulse

QNAP Security Advisories & CVEs

156 advisories tracked · QNAP PSIRT (security@qnap.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor QNAP CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your QNAP device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in QNAP's recent advisories.

Official source

QNAP PSIRT (security@qnap.com CNA) via NVD

QNAP is its own CVE Numbering Authority. VulniPulse ingests QNAP's CVEs from the NVD CNA feed (security@qnap.com), grouped by their official QSA advisory, and enriches each from the security-advisory page — the vendor's severity, affected apps/OS and the fixed build. Covers QTS, QuTS hero and QuTScloud (NAS operating systems), plus QVR, Qsync, HBS 3, Netatalk, Malware Remover, License Center and Photo/Video/Music Station — QNAP NAS are a relentless ransomware target (DeadBolt, Qlocker), so an alert-hungry community.

Latest QNAP advisories

Medium4.9QNAP

Medium [CVE-2024-53696] QTS: server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center.

A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01 ) and later QTS 4.5.4.2957 build 20241119 and later QuTS hero h4.5.4.2956 build 20241119 and later

CVE-2024-53696
QTSQuTS hero
Mar 7, 2025
Medium4.7QNAP

Medium [CVE-2024-53692] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later Affected products named by the advisory: QuTS hero.

CVE-2024-53692
QTSQuTS hero
Mar 7, 2025
Medium5.5QNAP

Medium [CVE-2024-50405] QTS: improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating…

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later Affected products named by the advisory: QuTS hero.

CVE-2024-50405
QTSQuTS hero
Mar 7, 2025
Medium5.3QNAP

Medium [CVE-2024-13086] QTS: exposure of sensitive information vulnerability has been reported to affect product.

An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QTS 5.2.0.2851 build 20240808 and later Affected products named by the advisory: QuTS hero.

CVE-2024-13086
QTSQuTS hero
Mar 7, 2025
Medium4.8QNAP

Medium [CVE-2023-23357] cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.5.0.738 ( 2023/03/06 ) and later

CVE-2023-23357
Unclassified
Dec 19, 2024
Medium5.5QNAP

Medium [CVE-2023-23356] QuFirewall: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QuFirewall 2.3.3 ( 2023/03/27 ) and later

CVE-2023-23356
Unclassified
Dec 19, 2024
Medium6.8QNAP

Medium [CVE-2022-27600] QTS: uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions.

An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2277 and later QuTS hero h4.5.4.2374 build 20230417 and later Affected products named by the advisory: QuTScloud.

CVE-2022-27600
QTSQuTS hero
Dec 19, 2024
Medium5.3QNAP

Medium [CVE-2024-48866] QTS: improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system…

An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-48866
QTSQuTS hero
Dec 6, 2024
Medium6.0QNAP

Medium [CVE-2024-38646] incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3.

An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the resource. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

CVE-2024-38646
Unclassified
Nov 22, 2024
Medium6.5QNAP

Medium [CVE-2024-38645] server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3.

A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

CVE-2024-38645
Unclassified
Nov 22, 2024
Medium6.5QNAP

Medium [CVE-2024-37050] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-37050
QTSQuTS hero
Nov 22, 2024
Medium4.9QNAP

Medium [CVE-2024-37048] QTS: NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-37048
QTSQuTS hero
Nov 22, 2024
Medium4.9QNAP

Medium [CVE-2024-37046] QTS: path traversal vulnerability has been reported to affect several QNAP operating system versions.

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read the contents of unexpected files and expose sensitive data. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-37046
QTSQuTS hero
Nov 22, 2024
Medium6.3QNAP

Medium [CVE-2024-32770] Photo Station: cross-site scripting (XSS) vulnerability has been reported to affect Photo Station.

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later

CVE-2024-32770
Applications
Nov 22, 2024
Medium5.4QNAP

Medium [CVE-2024-38640] cross-site scripting (XSS) vulnerability has been reported to affect Download Station.

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Download Station 5.8.6.283 ( 2024/06/21 ) and later

CVE-2024-38640
Unclassified
Sep 6, 2024
Medium6.3QNAP

Medium [CVE-2024-27126] cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3.

A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: Notes Station 3 3.9.6 and later

CVE-2024-27126
Unclassified
Sep 6, 2024
Medium4.7QNAP

Medium [CVE-2024-21906] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later Affected products named by the advisory: QuTS hero.

CVE-2024-21906
QTSQuTS hero
Sep 6, 2024
Medium5.9QNAP

Medium [CVE-2024-21904] QTS: path traversal vulnerability has been reported to affect several QNAP operating system versions.

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.7.2770 build 20240520 and later Affected products named by the advisory: QuTS hero.

CVE-2024-21904
QTSQuTS hero
Sep 6, 2024
Medium6.6QNAP

Medium [CVE-2024-21903] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVE-2024-21903
QTSQuTS hero
Sep 6, 2024
Medium5.4QNAP

Medium [CVE-2023-51368] QTS: NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to launch a denial-of-service (DoS) attack via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVE-2023-51368
QTSQuTS hero
Sep 6, 2024

← All vendors