Skip to content
VulniPulse

QNAP Security Advisories & CVEs

326 advisories tracked · QNAP PSIRT (security@qnap.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor QNAP CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your QNAP device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in QNAP's recent advisories.

Official source

QNAP PSIRT (security@qnap.com CNA) via NVD

QNAP is its own CVE Numbering Authority. VulniPulse ingests QNAP's CVEs from the NVD CNA feed (security@qnap.com), grouped by their official QSA advisory, and enriches each from the security-advisory page — the vendor's severity, affected apps/OS and the fixed build. Covers QTS, QuTS hero and QuTScloud (NAS operating systems), plus QVR, Qsync, HBS 3, Netatalk, Malware Remover, License Center and Photo/Video/Music Station — QNAP NAS are a relentless ransomware target (DeadBolt, Qlocker), so an alert-hungry community.

Latest QNAP advisories

Critical9.8QNAP

Critical [CVE-2024-38643] missing authentication for critical function vulnerability has been reported to affect Notes Station 3.

A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

CVE-2024-38643
Unclassified
Nov 22, 2024
High7.2QNAP

High [CVE-2024-50401] QTS: use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-50401
QTSQuTS hero
Nov 22, 2024
High8.8QNAP

High [CVE-2024-50397] QTS: use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-50397
QTSQuTS hero
Nov 22, 2024
High8.8QNAP

High [CVE-2024-50396] QTS: use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-50396
QTSQuTS hero
Nov 22, 2024
High8.8QNAP

High [CVE-2024-50395] authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on.

An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later

CVE-2024-50395
Unclassified
Nov 22, 2024
High7.8QNAP

High [CVE-2024-48861] OS command injection vulnerability has been reported to affect several product versions.

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and later

CVE-2024-48861
Unclassified
Nov 22, 2024
High7.5QNAP

High [CVE-2024-38647] exposure of sensitive information vulnerability has been reported to affect QNAP AI Core.

An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP AI Core 3.4.1 and later

CVE-2024-38647
Unclassified
Nov 22, 2024
High8.8QNAP

High [CVE-2024-38644] OS command injection vulnerability has been reported to affect Notes Station 3.

An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

CVE-2024-38644
Unclassified
Nov 22, 2024
High7.2QNAP

High [CVE-2024-37044] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-37044
QTSQuTS hero
Nov 22, 2024
Medium6.0QNAP

Medium [CVE-2024-38646] incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3.

An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the resource. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

CVE-2024-38646
Unclassified
Nov 22, 2024
Medium6.5QNAP

Medium [CVE-2024-38645] server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3.

A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

CVE-2024-38645
Unclassified
Nov 22, 2024
Medium4.9QNAP

Medium [CVE-2024-37048] QTS: NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-37048
QTSQuTS hero
Nov 22, 2024
Medium4.9QNAP

Medium [CVE-2024-37046] QTS: path traversal vulnerability has been reported to affect several QNAP operating system versions.

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read the contents of unexpected files and expose sensitive data. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

CVE-2024-37046
QTSQuTS hero
Nov 22, 2024
Medium6.3QNAP

Medium [CVE-2024-32770] Photo Station: cross-site scripting (XSS) vulnerability has been reported to affect Photo Station.

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later

CVE-2024-32770
Applications
Nov 22, 2024
High7.8QNAP

High [CVE-2024-38642] QuMagie: improper certificate validation vulnerability has been reported to affect QuMagie.

An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unspecified vectors. We have already fixed the vulnerability in the following version: QuMagie 2.3.1 and later

CVE-2024-38642
Applications
Sep 6, 2024
High7.8QNAP

High [CVE-2024-38641] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network users to execute commands via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later Affected products named by the advisory: QuTS hero.

CVE-2024-38641
QTSQuTS hero
Sep 6, 2024
High8.8QNAP

High [CVE-2024-32763] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later Affected products named by the advisory: QuTS hero.

CVE-2024-32763
QTSQuTS hero
Sep 6, 2024
High8.2QNAP

High [CVE-2024-32762] cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center.

A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QuLog Center 1.8.0.872 ( 2024/06/17 ) and later

CVE-2024-32762
Unclassified
Sep 6, 2024
High8.8QNAP

High [CVE-2024-21898] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVE-2024-21898
QTSQuTS hero
Sep 6, 2024
High8.9QNAP

High [CVE-2024-21897] QTS: cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVE-2024-21897
QTSQuTS hero
Sep 6, 2024

← All vendors