Qnap Quts Hero vulnerabilities
234 known vulnerabilities affecting qnap/quts_hero.
Total CVEs
234
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL15HIGH107MEDIUM109LOW3
Vulnerabilities
Page 3 of 12
CVE-2026-22893P3HIGHCVSS 7.2≥ h5.2.0.2737, < h5.2.9.3410≥ h5.3.0.3115, < h5.3.4.3500+1 more2026-06-10
CVE-2026-22893 [HIGH] CWE-78 CVE-2026-22893: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and later
QuTS hero h5.2.9.341
nvd
CVE-2025-66279P3HIGHCVSS 7.2≥ h5.2.0.2737, < h5.2.9.3410≥ h5.3.0.3115, < h5.3.4.3500+1 more2026-06-10
CVE-2025-66279 [HIGH] CWE-78 CVE-2025-66279: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and later
QuTS hero h5.2.9.341
nvd
CVE-2025-66273P3HIGHCVSS 7.2≥ h5.2.0.2737, < h5.2.9.3410≥ h5.3.0.3115, < h5.3.4.3500+1 more2026-06-10
CVE-2025-66273 [HIGH] CWE-78 CVE-2025-66273: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and later
QuTS hero h5.2.9.341
nvd
CVE-2021-28816P3HIGHCVSS 8.8fixed in h4.5.4.17712021-09-10
CVE-2021-28816 [HIGH] CWE-787 CVE-2021-28816: A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud
A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210
nvd
CVE-2025-47212P3HIGHCVSS 7.2vh5.2.0.2737vh5.2.0.2782+12 more2025-10-03
CVE-2025-47212 [HIGH] CWE-78 CVE-2025-47212: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.6.3195 build 20250715 and later
QuTS hero h5.2.6.319
nvd
CVE-2026-24719P3HIGHCVSS 7.2≥ h5.0.0, < h5.2.9.34992026-06-10
CVE-2026-24719 [HIGH] CWE-78 CVE-2026-24719: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3492 build 20260507 and later
QuTS hero h5.2.9.349
nvd
CVE-2024-14026P3HIGHCVSS 7.8vh5.1.0.2409vh5.1.0.2424+23 more2026-03-11
CVE-2024-14026 [HIGH] CWE-78 CVE-2024-14026: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and
nvd
CVE-2025-48725P3HIGHCVSS 8.1vh5.2.0.2737vh5.2.0.2782+16 more2026-02-11
CVE-2025-48725 [HIGH] CWE-120 CVE-2025-48725: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following version:
QuTS hero h5.3.2.3354 build 20251225 and later
nvd
CVE-2024-50396P3HIGHCVSS 8.8vh5.2.0.2737vh5.2.0.2782+5 more2024-11-22
CVE-2024-50396 [HIGH] CWE-134 CVE-2024-50396: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build 20241025 and later
QuTS hero h5.2.1.2
nvd
CVE-2021-44052P3HIGHCVSS 8.1fixed in h4.5.4.1771≥ h5.0.0.1772, < h5.0.0.19862022-05-05
CVE-2021-44052 [HIGH] CWE-59 CVE-2021-44052: An improper link resolution before file access ('Link Following') vulnerability has been reported to
An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed this vul
nvd
CVE-2025-30273P3HIGHCVSS 8.1vh5.2.0.2737vh5.2.0.2782+11 more2025-08-29
CVE-2025-30273 [HIGH] CWE-787 CVE-2025-30273: An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versi
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.5.3145 build 20250526 and later
QuTS hero h5.2.5.3138 build
nvd
CVE-2025-52863P3HIGHCVSS 8.1vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-52863 [HIGH] CWE-120 CVE-2025-52863: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS hero h5.2.7.3256 buil
nvd
CVE-2025-52872P3HIGHCVSS 8.1vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-52872 [HIGH] CWE-120 CVE-2025-52872: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS hero h5.2.7.3256 buil
nvd
CVE-2025-52864P3HIGHCVSS 8.1vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-52864 [HIGH] CWE-120 CVE-2025-52864: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS hero h5.2.7.3256 buil
nvd
CVE-2020-2508P3HIGHCVSS 7.2fixed in h4.5.1.14722021-01-11
CVE-2020-2508 [HIGH] CWE-77 CVE-2020-2508: A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later)
nvd
CVE-2025-62847P3HIGHCVSS 7.5vh5.2.0.2737vh5.2.0.2782+18 more2025-12-16
CVE-2025-62847 [HIGH] CWE-88 CVE-2025-62847: An improper neutralization of argument delimiters in a command vulnerability has been reported to af
An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3297 build 20251024 and later
QuTS hero h5.2.7.32
nvd
CVE-2025-66280P3HIGHCVSS 7.2≥ h5.2.0.2737, < h5.2.9.3410≥ h5.3.0.3115, < h5.3.4.3500+1 more2026-06-10
CVE-2025-66280 [HIGH] CWE-121 CVE-2025-66280: An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating s
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and
nvd
CVE-2024-27124P3HIGHCVSS 7.5≥ h4.5.0, < h4.5.4.2626≥ h5.0.0, < h5.1.3.2578+2 more2024-04-26
CVE-2024-27124 [HIGH] CWE-78 CVE-2024-27124: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QTS 4.5.4.2627 build 20231225 and later
QuTS hero h5.1.
nvd
CVE-2024-21900P3MEDIUMCVSS 6.5fixed in h5.1.3.2578vh5.1.3.25782024-03-08
CVE-2024-21900 [MEDIUM] CWE-74 CVE-2024-21900: An injection vulnerability has been reported to affect several QNAP operating system versions. If ex
An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QuTS hero h5.1.3.2578 build 20231110 and later
QuT
nvd
CVE-2023-34980P3HIGHCVSS 8.4≥ h4.5.0, < h4.5.4.2626vh4.5.4.26262024-03-08
CVE-2023-34980 [HIGH] CWE-78 CVE-2023-34980: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 4.5.4.2627 build 20231225 and later
QuTS hero h4.5.4.2626 build 2023
nvd