Skip to content
VulniPulse

QNAP Security Advisories & CVEs

326 advisories tracked · QNAP PSIRT (security@qnap.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor QNAP CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your QNAP device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in QNAP's recent advisories.

Official source

QNAP PSIRT (security@qnap.com CNA) via NVD

QNAP is its own CVE Numbering Authority. VulniPulse ingests QNAP's CVEs from the NVD CNA feed (security@qnap.com), grouped by their official QSA advisory, and enriches each from the security-advisory page — the vendor's severity, affected apps/OS and the fixed build. Covers QTS, QuTS hero and QuTScloud (NAS operating systems), plus QVR, Qsync, HBS 3, Netatalk, Malware Remover, License Center and Photo/Video/Music Station — QNAP NAS are a relentless ransomware target (DeadBolt, Qlocker), so an alert-hungry community.

Latest QNAP advisories

Medium6.5QNAP

Medium [CVE-2025-30268] QTS: NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

CVE-2025-30268
QTSQuTS hero
Aug 29, 2025
Medium6.5QNAP

Medium [CVE-2025-30265] QTS: buffer overflow vulnerability has been reported to affect several QNAP operating system versions.

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

CVE-2025-30265
QTSQuTS hero
Aug 29, 2025
Medium6.5QNAP

Medium [CVE-2025-30263] Qsync: NULL pointer dereference vulnerability has been reported to affect Qsync Central.

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.0 ( 2025/06/13 ) and later

CVE-2025-30263
Applications
Aug 29, 2025
Medium6.5QNAP

Medium [CVE-2025-30261] Qsync: allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central.

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.0 ( 2025/06/13 ) and later

CVE-2025-30261
Applications
Aug 29, 2025
Medium6.5QNAP

Medium [CVE-2025-30260] Qsync: allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central.

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

CVE-2025-30260
Applications
Aug 29, 2025
Medium6.5QNAP

Medium [CVE-2025-29900] allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5.

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4907 and later

CVE-2025-29900
Unclassified
Aug 29, 2025
Medium6.5QNAP

Medium [CVE-2025-29898] Qsync: uncontrolled resource consumption vulnerability has been reported to affect Qsync Central.

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

CVE-2025-29898
Applications
Aug 29, 2025
Medium6.5QNAP

Medium [CVE-2025-29889] NULL pointer dereference vulnerability has been reported to affect File Station 5.

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4907 and later

CVE-2025-29889
Unclassified
Aug 29, 2025
Medium4.8QNAP

Medium [CVE-2025-22483] License Center: cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: License Center 1.8.51 and later

CVE-2025-22483
Unclassified
Aug 29, 2025
Medium5.4QNAP

Medium [CVE-2024-12923] Photo Station: cross-site scripting (XSS) vulnerability has been reported to affect Photo Station.

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: Photo Station 6.4.5 ( 2025/01/02 ) and later

CVE-2024-12923
Applications
Aug 29, 2025
UnratedQNAP

Unknown [CVE-2025-52861] path traversal vulnerability has been reported to affect VioStor.

A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621 and later

CVE-2025-52861
Unclassified
Aug 29, 2025
Medium6.5QNAP

Medium [CVE-2025-29901] NULL pointer dereference vulnerability has been reported to affect File Station 5.

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4933 and later

CVE-2025-29901
Unclassified
Aug 26, 2025
High8.1QNAP

High [CVE-2025-47206] out-of-bounds write vulnerability has been reported to affect File Station 5.

An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4933 and later

CVE-2025-47206
Unclassified
Aug 18, 2025
High8.8QNAP

High [CVE-2025-33031] improper certificate validation vulnerability has been reported to affect File Station 5.

An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVE-2025-33031
Unclassified
Jun 6, 2025
High8.8QNAP

High [CVE-2025-29892] Qsync: SQL injection vulnerability has been reported to affect Qsync Central.

An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later

CVE-2025-29892
Applications
Jun 6, 2025
High8.8QNAP

High [CVE-2025-29885] improper certificate validation vulnerability has been reported to affect File Station 5.

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later

CVE-2025-29885
Unclassified
Jun 6, 2025
High7.5QNAP

High [CVE-2025-29877] NULL pointer dereference vulnerability has been reported to affect File Station 5.

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVE-2025-29877
Unclassified
Jun 6, 2025
High7.5QNAP

High [CVE-2025-29872] allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5.

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVE-2025-29872
Unclassified
Jun 6, 2025
High8.1QNAP

High [CVE-2025-22482] Qsync: use of externally-controlled format string vulnerability has been reported to affect Qsync Central.

A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later

CVE-2025-22482
Applications
Jun 6, 2025
High8.8QNAP

High [CVE-2025-22481] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build 20250321 and later Affected products named by the advisory: QuTS hero.

CVE-2025-22481
QTSQuTS hero
Jun 6, 2025

← All vendors