cbcvebase.

Qnap Qts vulnerabilities

283 known vulnerabilities affecting qnap/qts.

Total CVEs
283
CISA KEV
7
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH116MEDIUM120LOW3

Vulnerabilities

Page 3 of 15
CVE-2018-0730P2CRITICALCVSS 9.8v4.2.6v4.3.3.0868+23 more2019-12-04
CVE-2018-0730 [CRITICAL] CWE-77 CVE-2018-0730: This command injection vulnerability in File Station allows attackers to execute commands on the aff This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
nvd
CVE-2021-28800P2CRITICALCVSS 9.8fixed in 4.3.3.1624≥ 4.3.4, < 4.3.6.16632021-06-24
CVE-2021-28800 [CRITICAL] CWE-78 CVE-2021-28800: A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QT A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.3.6.1663 Build 20210504; versions prior to 4.3.3.1624 Build 20210416. This
nvd
CVE-2023-39303P2CRITICALCVSS 9.8v5.1.0.2348v5.1.0.2399+6 more2024-02-02
CVE-2023-39303 [CRITICAL] CWE-287 CVE-2023-39303: An improper authentication vulnerability has been reported to affect several QNAP operating system v An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 buil
nvd
CVE-2021-44051P2HIGHCVSS 8.8≥ 5.0.0.1716, < 5.0.0.1986≥ 4.3.3.0174, < 4.3.3.1945+4 more2022-05-05
CVE-2021-44051 [HIGH] CWE-77 CVE-2021-44051: A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1986 build 20
nvd
CVE-2024-48859P2CRITICALCVSS 9.1v5.1.0.2348v5.1.0.2399+20 more2024-12-06
CVE-2024-48859 [CRITICAL] CWE-287 CVE-2024-48859: An improper authentication vulnerability has been reported to affect several QNAP operating system v An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114
nvd
CVE-2024-21898P2HIGHCVSS 8.8v5.1.0.2348v5.1.0.2399+9 more2024-09-06
CVE-2024-21898 [HIGH] CWE-78 CVE-2024-21898: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and l
nvd
CVE-2023-39297P2HIGHCVSS 8.8v4.5.4.1715v4.5.4.1723+19 more2024-02-02
CVE-2023-39297 [HIGH] CWE-78 CVE-2023-39297: An OS command injection vulnerability has been reported to affect several QNAP operating system vers An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627 build 20231225 and later Q
nvd
CVE-2017-17033P2CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17033 [CRITICAL] CWE-119 CVE-2017-17033: A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3 A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2017-17028P2CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17028 [CRITICAL] CWE-119 CVE-2017-17028: A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026 A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2020-25847P2HIGHCVSS 8.8fixed in 4.5.1.14952020-12-29
CVE-2020-25847 [HIGH] CWE-77 CVE-2020-25847: This command injection vulnerability allows attackers to execute arbitrary commands in a compromised This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.
nvd
CVE-2023-23362P2HIGHCVSS 8.8≥ 4.5.4, < 4.5.4.2374≥ 5.0.1, < 5.0.1.23762023-09-22
CVE-2023-23362 [HIGH] CWE-78 CVE-2023-23362: An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploit An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via susceptible QNAP devices. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later
nvd
CVE-2017-17032P3CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17032 [CRITICAL] CWE-119 CVE-2017-17032: A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3 A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2017-17031P3CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17031 [CRITICAL] CWE-119 CVE-2017-17031: A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3 A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2023-50364P3HIGHCVSS 8.8v5.1.0.2348v5.1.0.2399+9 more2024-04-26
CVE-2023-50364 [HIGH] CWE-120 CVE-2023-50364: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 bu
nvd
CVE-2023-50361P3HIGHCVSS 8.8v5.1.0.2348v5.1.0.2399+9 more2024-04-26
CVE-2023-50361 [HIGH] CWE-120 CVE-2023-50361: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 bu
nvd
CVE-2023-50362P3HIGHCVSS 8.8v5.1.0.2348v5.1.0.2399+9 more2024-04-26
CVE-2023-50362 [HIGH] CWE-120 CVE-2023-50362: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 bu
nvd
CVE-2024-32763P3HIGHCVSS 8.8v5.1.0.2348v5.1.0.2399+11 more2024-09-06
CVE-2024-32763 [HIGH] CWE-120 CVE-2024-32763: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 bu
nvd
CVE-2017-17029P3CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17029 [CRITICAL] CWE-119 CVE-2017-17029: A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.03 A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2017-17030P3CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17030 [CRITICAL] CWE-119 CVE-2017-17030: A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.03 A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
CVE-2017-17027P3CRITICALCVSS 9.8≤ 4.3.3.0378v4.3.4.0358+4 more2017-12-21
CVE-2017-17027 [CRITICAL] CWE-119 CVE-2017-17027: A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
nvd
Qnap Qts vulnerabilities | cvebase