Skip to content
VulniPulse

QNAP Security Advisories & CVEs

326 advisories tracked · QNAP PSIRT (security@qnap.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor QNAP CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your QNAP device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in QNAP's recent advisories.

Official source

QNAP PSIRT (security@qnap.com CNA) via NVD

QNAP is its own CVE Numbering Authority. VulniPulse ingests QNAP's CVEs from the NVD CNA feed (security@qnap.com), grouped by their official QSA advisory, and enriches each from the security-advisory page — the vendor's severity, affected apps/OS and the fixed build. Covers QTS, QuTS hero and QuTScloud (NAS operating systems), plus QVR, Qsync, HBS 3, Netatalk, Malware Remover, License Center and Photo/Video/Music Station — QNAP NAS are a relentless ransomware target (DeadBolt, Qlocker), so an alert-hungry community.

Latest QNAP advisories

High7.8QNAP

High [CVE-2024-13088] improper authentication vulnerability has been reported to affect QHora.

An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QuRouter 2.5.0.140 and later

CVE-2024-13088
Unclassified
Jun 6, 2025
Medium6.5QNAP

Medium [CVE-2025-33035] path traversal vulnerability has been reported to affect File Station 5.

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVE-2025-33035
Unclassified
Jun 6, 2025
Medium5.5QNAP

Medium [CVE-2025-29871] out-of-bounds read vulnerability has been reported to affect File Station 5.

An out-of-bounds read vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later

CVE-2025-29871
Unclassified
Jun 6, 2025
Medium5.4QNAP

Medium [CVE-2024-56805] QTS: buffer overflow vulnerability has been reported to affect several QNAP operating system versions.

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build 20250321 and later Affected products named by the advisory: QuTS hero.

CVE-2024-56805
QTSQuTS hero
Jun 6, 2025
Medium5.4QNAP

Medium [CVE-2024-50406] License Center: cross-site scripting (XSS) vulnerability has been reported to affect License Center.

A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: License Center 1.9.49 and later

CVE-2024-50406
Unclassified
Jun 6, 2025
Medium6.7QNAP

Medium [CVE-2024-13087] command injection vulnerability has been reported to affect QHora.

A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.6.028 and later

CVE-2024-13087
Unclassified
Jun 6, 2025
Critical9.1QNAP

Critical [CVE-2024-53695] HBS: buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to modify memory or crash processes. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.4.952 and later

CVE-2024-53695
Backup (HBS)
Mar 7, 2025
Critical9.8QNAP

Critical [CVE-2024-50390] command injection vulnerability has been reported to affect QHora.

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

CVE-2024-50390
Unclassified
Mar 7, 2025
Critical9.1QNAP

Critical [CVE-2024-48864] files or directories accessible to external parties vulnerability has been reported to affect File Station 5.

A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers to read/write files or directories. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4741 and later

CVE-2024-48864
Unclassified
Mar 7, 2025
High7.2QNAP

High [CVE-2024-53700] command injection vulnerability has been reported to affect QHora.

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.6.028 and later

CVE-2024-53700
Unclassified
Mar 7, 2025
High7.2QNAP

High [CVE-2024-53699] QTS: out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions.

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later Affected products named by the advisory: QuTS hero.

CVE-2024-53699
QTSQuTS hero
Mar 7, 2025
High7.1QNAP

High [CVE-2024-53693] QTS: improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating…

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later Affected products named by the advisory: QuTS hero.

CVE-2024-53693
QTSQuTS hero
Mar 7, 2025
High8.8QNAP

High [CVE-2024-50394] Helpdesk: improper certificate validation vulnerability has been reported to affect Helpdesk.

An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: Helpdesk 3.3.3 and later

CVE-2024-50394
Unclassified
Mar 7, 2025
High7.2QNAP

High [CVE-2024-38638] QTS: out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions.

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. QTS 5.2.x/QuTS hero h5.2.x are not affected. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later

CVE-2024-38638
QTSQuTS hero
Mar 7, 2025
Medium4.9QNAP

Medium [CVE-2024-53698] QTS: double free vulnerability has been reported to affect several QNAP operating system versions.

A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later Affected products named by the advisory: QuTS hero.

CVE-2024-53698
QTSQuTS hero
Mar 7, 2025
Medium4.9QNAP

Medium [CVE-2024-53696] QTS: server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center.

A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01 ) and later QTS 4.5.4.2957 build 20241119 and later QuTS hero h4.5.4.2956 build 20241119 and later

CVE-2024-53696
QTSQuTS hero
Mar 7, 2025
Medium4.7QNAP

Medium [CVE-2024-53692] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later Affected products named by the advisory: QuTS hero.

CVE-2024-53692
QTSQuTS hero
Mar 7, 2025
Medium5.5QNAP

Medium [CVE-2024-50405] QTS: improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating…

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later Affected products named by the advisory: QuTS hero.

CVE-2024-50405
QTSQuTS hero
Mar 7, 2025
Medium5.3QNAP

Medium [CVE-2024-13086] QTS: exposure of sensitive information vulnerability has been reported to affect product.

An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QTS 5.2.0.2851 build 20240808 and later Affected products named by the advisory: QuTS hero.

CVE-2024-13086
QTSQuTS hero
Mar 7, 2025
UnratedQNAP

Unknown [CVE-2024-53694] Qsync: time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions.

A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources. We have already fixed the vulnerability in the following versions: QVPN Device Client for Mac 2.2.5 and later Qfinder Pro Mac 7.11.1 and later Affected product named by the advisory: Qsync.

CVE-2024-53694
Applications
Mar 7, 2025

← All vendors