Qnap Qts vulnerabilities
283 known vulnerabilities affecting qnap/qts.
Total CVEs
283
CISA KEV
7
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH116MEDIUM120LOW3
Vulnerabilities
Page 2 of 15
CVE-2024-32766P2CRITICALCVSS 10.0fixed in 4.5.4.2627≥ 5.0.0, < 5.1.3.2578+2 more2024-04-26
CVE-2024-32766 [CRITICAL] CWE-77 CVE-2024-32766: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QTS 4.5.4.2627 build 20231225 and later
QuTS hero h
nvd
CVE-2025-59385P2CRITICALCVSS 9.8v5.2.0.2737v5.2.0.2744+15 more2025-12-16
CVE-2025-59385 [CRITICAL] CWE-290 CVE-2025-59385: An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operatin
An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3297 build
nvd
CVE-2017-5227P3HIGHCVSS 7.5PoC≤ 4.2.42017-03-23
CVE-2017-5227 [HIGH] CWE-200 CVE-2017-5227: QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator pas
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file.
nvd
CVE-2024-53691P2HIGHCVSS 8.8v5.1.0.2348v5.1.0.2399+14 more2024-12-06
CVE-2024-53691 [HIGH] CWE-59 CVE-2024-53691: A link following vulnerability has been reported to affect several QNAP operating system versions. I
A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations.
We have already fixed the vulnerability in the following versions:
QTS 5.1.8.2823 build 20240712 and later
QTS 5
nvd
CVE-2024-50393P2CRITICALCVSS 9.8v5.1.0.2348v5.1.0.2399+20 more2024-12-06
CVE-2024-50393 [CRITICAL] CWE-78 CVE-2024-50393: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and later
QTS 5.2.2.2950 build 20241114 and later
QuTS her
nvd
CVE-2025-62849P2CRITICALCVSS 9.8v5.2.0.2737v5.2.0.2744+15 more2025-12-16
CVE-2025-62849 [CRITICAL] CWE-89 CVE-2025-62849: An SQL injection vulnerability has been reported to affect several QNAP operating system versions. T
An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3297 build 20251024 and later
QuTS hero h5.2.7.3297 build 20251024 and late
nvd
CVE-2023-51364P2HIGHCVSS 7.5≥ 4.5.1, < 4.5.4.2627≥ 5.1.0, < 5.1.4.2596+2 more2024-04-26
CVE-2023-51364 [HIGH] CWE-22 CVE-2023-51364: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QTS 4.5.4.2627
nvd
CVE-2023-45025P2CRITICALCVSS 9.8v4.5.4.1715v4.5.4.1723+19 more2024-02-02
CVE-2023-45025 [CRITICAL] CWE-77 CVE-2023-45025: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QTS 4.5.4.2627 build 20231225 and later
QuTS hero h
nvd
CVE-2025-66277P2CRITICALCVSS 9.8v5.2.0.2737v5.2.0.2744+17 more2026-02-11
CVE-2025-66277 [CRITICAL] CWE-59 CVE-2025-66277: A link following vulnerability has been reported to affect several QNAP operating system versions. T
A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations.
We have already fixed the vulnerability in the following versions:
QTS 5.2.8.3350 build 20251216 and later
QuTS hero h5.3.2.3354 build 202512
nvd
CVE-2023-51365P2HIGHCVSS 7.5≥ 4.5.1, < 4.5.4.2627≥ 5.1.0, < 5.1.4.2596+2 more2024-04-26
CVE-2023-51365 [HIGH] CWE-22 CVE-2023-51365: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QTS 4.5.4.2627
nvd
CVE-2025-30264P2HIGHCVSS 8.8v5.2.0.2737v5.2.0.2744+11 more2025-08-29
CVE-2025-30264 [HIGH] CWE-77 CVE-2025-30264: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.5.3145 build 20250526 and later
QuTS hero h5.2.5.3138 build 20
nvd
CVE-2025-22481P2HIGHCVSS 8.8v5.2.0.2737v5.2.0.2744+9 more2025-06-06
CVE-2025-22481 [HIGH] CWE-77 CVE-2025-22481: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.4.3079 build 20250321 and later
QuTS hero h5.2.4.3079 bu
nvd
CVE-2021-28804P2CRITICALCVSS 9.8≤ 4.5.1.15402021-07-01
CVE-2021-28804 [CRITICAL] CWE-78 CVE-2021-28804: A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, th
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions prior to h4.5.1.1582 build 20210
nvd
CVE-2021-28802P2CRITICALCVSS 9.8fixed in 4.5.1.15402021-07-01
CVE-2021-28802 [CRITICAL] CWE-78 CVE-2021-28802: A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, th
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions prior to h4.5.1.1582 build 20210
nvd
CVE-2018-14746P2CRITICALCVSS 9.8v4.2.6v4.3.3+2 more2018-11-28
CVE-2018-14746 [CRITICAL] CWE-77 CVE-2018-14746: Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 bui
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to run arbitrary commands on the NAS.
nvd
CVE-2019-7198P2CRITICALCVSS 9.8fixed in 4.4.3.1354fixed in 4.5.1.14562020-12-10
CVE-2019-7198 [CRITICAL] CWE-77 CVE-2019-7198: This command injection vulnerability allows attackers to execute arbitrary commands in a compromised
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later
nvd
CVE-2017-10700P2CRITICALCVSS 9.8v4.3.3.02292017-09-19
CVE-2017-10700 [CRITICAL] CWE-20 CVE-2017-10700: In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execu
In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.
nvd
CVE-2023-34974P2HIGHCVSS 8.8v4.5.4.1715v4.5.4.1723+11 more2024-09-06
CVE-2023-34974 [HIGH] CWE-78 CVE-2023-34974: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
QuTScloud, QVR, QES are not affected.
We have already fixed the vulnerability in the following versions:
QTS 4.5.4.2790 build 20240605 and later
QuTS hero h4.5.4.
nvd
CVE-2022-27596P2CRITICALCVSS 9.8≥ 5.0.1, < 5.0.1.22342023-01-30
CVE-2022-27596 [CRITICAL] CWE-89 CVE-2022-27596: A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this v
A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code.
We have already fixed this vulnerability in the following versions of QuTS hero, QTS:
QuTS hero h5.0.1.2248 build 20221215 and later
QTS 5.0.1.2234 build 20221201 and later
nvd
CVE-2018-0712P2CRITICALCVSS 9.8v4.2.6v4.3.3+1 more2018-06-21
CVE-2018-0712 [CRITICAL] CWE-77 CVE-2018-0712: Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 201
Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.
nvd