Qnap Qts vulnerabilities
283 known vulnerabilities affecting qnap/qts.
Total CVEs
283
CISA KEV
7
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH116MEDIUM120LOW3
Vulnerabilities
Page 5 of 15
CVE-2020-2492P3HIGHCVSS 7.2fixed in 4.4.3.14212020-11-16
CVE-2020-2492 [HIGH] CWE-77 CVE-2020-2492: If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
nvd
CVE-2024-50396P3HIGHCVSS 8.8v5.2.0.2737v5.2.0.2744+5 more2024-11-22
CVE-2024-50396 [HIGH] CWE-134 CVE-2024-50396: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build 20241025 and later
QuTS hero h5.2.1.2
nvd
CVE-2021-44052P3HIGHCVSS 8.1≥ 5.0.0.1716, < 5.0.0.1986≥ 4.3.3.0174, < 4.3.3.1945+4 more2022-05-05
CVE-2021-44052 [HIGH] CWE-59 CVE-2021-44052: An improper link resolution before file access ('Link Following') vulnerability has been reported to
An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed this vul
nvd
CVE-2025-30273P3HIGHCVSS 8.1v5.2.0.2737v5.2.0.2744+11 more2025-08-29
CVE-2025-30273 [HIGH] CWE-787 CVE-2025-30273: An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versi
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.5.3145 build 20250526 and later
QuTS hero h5.2.5.3138 build
nvd
CVE-2025-52863P3HIGHCVSS 8.1v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-52863 [HIGH] CWE-120 CVE-2025-52863: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS hero h5.2.7.3256 buil
nvd
CVE-2025-52872P3HIGHCVSS 8.1v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-52872 [HIGH] CWE-120 CVE-2025-52872: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS hero h5.2.7.3256 buil
nvd
CVE-2025-52864P3HIGHCVSS 8.1v5.2.0.2737v5.2.0.2744+14 more2026-01-02
CVE-2025-52864 [HIGH] CWE-120 CVE-2025-52864: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS hero h5.2.7.3256 buil
nvd
CVE-2020-2508P3HIGHCVSS 7.2fixed in 4.5.1.14562021-01-11
CVE-2020-2508 [HIGH] CWE-77 CVE-2020-2508: A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later)
nvd
CVE-2025-62847P3HIGHCVSS 7.5v5.2.0.2737v5.2.0.2744+15 more2025-12-16
CVE-2025-62847 [HIGH] CWE-88 CVE-2025-62847: An improper neutralization of argument delimiters in a command vulnerability has been reported to af
An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3297 build 20251024 and later
QuTS hero h5.2.7.32
nvd
CVE-2025-66280P3HIGHCVSS 7.2≥ 5.2.0.2737, < 5.2.9.34102026-06-10
CVE-2025-66280 [HIGH] CWE-121 CVE-2025-66280: An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating s
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and
nvd
CVE-2024-27124P3HIGHCVSS 7.5≥ 4.5.1, < 4.5.4.2627≥ 5.0.0, < 5.1.3.2578+2 more2024-04-26
CVE-2024-27124 [HIGH] CWE-78 CVE-2024-27124: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QTS 4.5.4.2627 build 20231225 and later
QuTS hero h5.1.
nvd
CVE-2024-21900P3MEDIUMCVSS 6.5fixed in 5.1.3.2578v5.1.3.25782024-03-08
CVE-2024-21900 [MEDIUM] CWE-74 CVE-2024-21900: An injection vulnerability has been reported to affect several QNAP operating system versions. If ex
An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QuTS hero h5.1.3.2578 build 20231110 and later
QuT
nvd
CVE-2023-34980P3HIGHCVSS 8.4≥ 4.5.1, < 4.5.4.2627v4.5.4.26272024-03-08
CVE-2023-34980 [HIGH] CWE-78 CVE-2023-34980: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 4.5.4.2627 build 20231225 and later
QuTS hero h4.5.4.2626 build 2023
nvd
CVE-2023-50363P3HIGHCVSS 8.1v5.1.0.2348v5.1.0.2399+9 more2024-04-26
CVE-2023-50363 [HIGH] CWE-285 CVE-2023-50363: An incorrect authorization vulnerability has been reported to affect several QNAP operating system v
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.6.2722 build 20240402 and later
QuTS hero h5.1.6.2
nvd
CVE-2024-21902P3HIGHCVSS 8.1v5.1.0.2348v5.1.0.2399+10 more2024-05-21
CVE-2024-21902 [HIGH] CWE-200 CVE-2024-21902: An incorrect permission assignment for critical resource vulnerability has been reported to affect s
An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network.
We have already fixed the vulnerability in the following version:
QTS 5.1.7.2770 build 20240520 and lat
nvd
CVE-2023-39300P3HIGHCVSS 7.2v4.3.6.0895v4.3.6.0907+62 more2024-09-06
CVE-2023-39300 [HIGH] CWE-78 CVE-2023-39300: An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vuln
An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 4.3.6.2805 build 20240619 and later
QTS 4.3.4.2814 build 20240618 and later
QTS 4.3.3.2784 build
nvd
CVE-2024-21905P3HIGHCVSS 8.2≥ 5.0.0, < 5.1.3.2578v5.1.3.25782024-04-26
CVE-2024-21905 [HIGH] CWE-190 CVE-2024-21905: An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating s
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QuTS hero h5.1.3.2578 b
nvd
CVE-2021-34343P3HIGHCVSS 7.2fixed in 4.3.3.1693≥ 4.3.4, < 4.3.6.1750+2 more2021-09-10
CVE-2021-34343 [HIGH] CWE-787 CVE-2021-34343: A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud
A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210
nvd
CVE-2023-23367P3HIGHCVSS 7.2v5.0.0.1716v5.0.0.1785+18 more2023-11-10
CVE-2023-23367 [HIGH] CWE-78 CVE-2023-23367: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2376 build 20230421 and later
QuTS hero h5.0.1.2376 build 2023
nvd
CVE-2023-47566P3HIGHCVSS 7.2v5.1.0.2348v5.1.0.2399+8 more2024-02-02
CVE-2023-47566 [HIGH] CWE-78 CVE-2023-47566: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116 and later
QuTS hero h5.1.5.2647 build 2024
nvd