Skip to content
VulniPulse

QNAP Security Advisories & CVEs

326 advisories tracked · QNAP PSIRT (security@qnap.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor QNAP CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your QNAP device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in QNAP's recent advisories.

Official source

QNAP PSIRT (security@qnap.com CNA) via NVD

QNAP is its own CVE Numbering Authority. VulniPulse ingests QNAP's CVEs from the NVD CNA feed (security@qnap.com), grouped by their official QSA advisory, and enriches each from the security-advisory page — the vendor's severity, affected apps/OS and the fixed build. Covers QTS, QuTS hero and QuTScloud (NAS operating systems), plus QVR, Qsync, HBS 3, Netatalk, Malware Remover, License Center and Photo/Video/Music Station — QNAP NAS are a relentless ransomware target (DeadBolt, Qlocker), so an alert-hungry community.

Latest QNAP advisories

High7.3QNAP

High [CVE-2023-23354] cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.5.0.738 ( 2023/03/06 ) and later

CVE-2023-23354
Unclassified
Dec 19, 2024
High7.8QNAP

High [CVE-2022-27595] insecure library loading vulnerability has been reported to affect QVPN Device Client.

An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QVPN Windows 2.0.0.1316 and later

CVE-2022-27595
Unclassified
Dec 19, 2024
Medium4.8QNAP

Medium [CVE-2023-23357] cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.5.0.738 ( 2023/03/06 ) and later

CVE-2023-23357
Unclassified
Dec 19, 2024
Medium5.5QNAP

Medium [CVE-2023-23356] QuFirewall: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QuFirewall 2.3.3 ( 2023/03/27 ) and later

CVE-2023-23356
Unclassified
Dec 19, 2024
Medium6.8QNAP

Medium [CVE-2022-27600] QTS: uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions.

An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2277 and later QuTS hero h4.5.4.2374 build 20230417 and later Affected products named by the advisory: QuTScloud.

CVE-2022-27600
QTSQuTS hero
Dec 19, 2024
Critical9.8QNAP

Critical [CVE-2024-50393] QTS: command injection vulnerability has been reported to affect several QNAP operating system versions.

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-50393
QTSQuTS hero
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-50389] SQL injection vulnerability has been reported to affect QuRouter.

A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

CVE-2024-50389
Unclassified
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-50388] HBS: OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later

CVE-2024-50388
Backup (HBS)
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-50387] SQL injection vulnerability has been reported to affect several QNAP operating system versions.

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later

CVE-2024-50387
Unclassified
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-48863] License Center: command injection vulnerability has been reported to affect License Center.

A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: License Center 1.9.43 and later

CVE-2024-48863
Unclassified
Dec 6, 2024
Critical9.1QNAP

Critical [CVE-2024-48859] QTS: improper authentication vulnerability has been reported to affect several QNAP operating system versions.

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-48859
QTSQuTS hero
Dec 6, 2024
High8.8QNAP

High [CVE-2024-53691] QTS: link following vulnerability has been reported to affect several QNAP operating system versions.

A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QTS 5.2.0.2802 build 20240620 and later Affected products named by the advisory: QuTS hero.

CVE-2024-53691
QTSQuTS hero
Dec 6, 2024
High8.8QNAP

High [CVE-2024-50404] Qsync: link following vulnerability has been reported to affect Qsync Central.

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and later

CVE-2024-50404
Applications
Dec 6, 2024
High7.2QNAP

High [CVE-2024-50403] QTS: use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-50403
QTSQuTS hero
Dec 6, 2024
High7.2QNAP

High [CVE-2024-50402] QTS: use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-50402
QTSQuTS hero
Dec 6, 2024
High7.5QNAP

High [CVE-2024-48868] QTS: improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating…

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-48868
QTSQuTS hero
Dec 6, 2024
High7.5QNAP

High [CVE-2024-48865] QTS: improper certificate validation vulnerability has been reported to affect several QNAP operating system versions.

An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network access to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-48865
QTSQuTS hero
Dec 6, 2024
Medium5.3QNAP

Medium [CVE-2024-48866] QTS: improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system…

An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5.2.2.2952 build 20241116 and later

CVE-2024-48866
QTSQuTS hero
Dec 6, 2024
Critical9.8QNAP

Critical [CVE-2024-48862] link following vulnerability has been reported to affect QuLog Center.

A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.831 ( 2024/10/15 ) and later

CVE-2024-48862
Unclassified
Nov 22, 2024
Critical9.8QNAP

Critical [CVE-2024-48860] OS command injection vulnerability has been reported to affect several product versions.

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.3.103 and later

CVE-2024-48860
Unclassified
Nov 22, 2024

← All vendors