Skip to content
VulniPulse

QNAP Security Advisories & CVEs

156 advisories tracked · QNAP PSIRT (security@qnap.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor QNAP CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your QNAP device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in QNAP's recent advisories.

Official source

QNAP PSIRT (security@qnap.com CNA) via NVD

QNAP is its own CVE Numbering Authority. VulniPulse ingests QNAP's CVEs from the NVD CNA feed (security@qnap.com), grouped by their official QSA advisory, and enriches each from the security-advisory page — the vendor's severity, affected apps/OS and the fixed build. Covers QTS, QuTS hero and QuTScloud (NAS operating systems), plus QVR, Qsync, HBS 3, Netatalk, Malware Remover, License Center and Photo/Video/Music Station — QNAP NAS are a relentless ransomware target (DeadBolt, Qlocker), so an alert-hungry community.

Latest QNAP advisories

Medium5.8QNAP

Medium [CVE-2020-2504] If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station.

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

CVE-2020-2504
Unclassified
Dec 24, 2020
Medium6.3QNAP

Medium [CVE-2020-2499] hard-coded password vulnerability has been reported to affect earlier versions of QES.

A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.

CVE-2020-2499
Unclassified
Dec 24, 2020
Medium6.1QNAP

Medium [CVE-2020-2498] QTS: If exploited, this cross-site scripting vulnerability could

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later

CVE-2020-2498
QTSQuTS hero
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2497] QTS: If exploited, this cross-site scripting vulnerability could

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later

CVE-2020-2497
QTSQuTS hero
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2496] QTS: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later

CVE-2020-2496
QTSQuTS hero
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2494] QTS: This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code.

This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12 and later

CVE-2020-2494
QTSQuTS heroApplications
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2493] Multimedia Console: This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code.

This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in Multimedia Console 1.1.5 and later.

CVE-2020-2493
Applications
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2491] QTS: This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code.

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and later QTS 4.3.4: Photo Station 5.7.13 and later QTS 4.3.3: Photo Station 5.4.10 and later QTS 4.2.6: Photo Station 5.2.11 and later

CVE-2020-2491
QTSApplications
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2018-19956] Photo Station: The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station.

The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc.

CVE-2018-19956
Applications
Nov 2, 2020
Medium6.1QNAP

Medium [CVE-2018-19951] Music Station: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.

CVE-2018-19951
Applications
Nov 2, 2020
Medium6.1QNAP Exploited CISA KEV

Medium [CVE-2018-19953] QTS: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CVE-2018-19953
QTS
Oct 28, 2020
Medium4.3QNAP

Medium [CVE-2018-19947] Helpdesk: The vulnerability have been reported to affect earlier versions of Helpdesk.

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.

CVE-2018-19947
Unclassified
Sep 11, 2020
Medium4.2QNAP

Medium [CVE-2018-19946] Helpdesk: The vulnerability have been reported to affect earlier versions of Helpdesk.

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.

CVE-2018-19946
Unclassified
Sep 11, 2020
Medium4.8QNAP

Medium [CVE-2019-7185] This cross-site scripting (XSS) vulnerability in Music Station

This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.

CVE-2019-7185
Applications
Dec 5, 2019
Medium4.8QNAP

Medium [CVE-2019-7184] This cross-site scripting (XSS) vulnerability in Video Station

This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Station to their latest versions.

CVE-2019-7184
Applications
Dec 5, 2019
Medium4.8QNAP

Medium [CVE-2019-7197] QTS: stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS.

A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.

CVE-2019-7197
QTS
Dec 4, 2019

← All vendors