Qnap Quts Hero vulnerabilities
234 known vulnerabilities affecting qnap/quts_hero.
Total CVEs
234
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL15HIGH107MEDIUM109LOW3
Vulnerabilities
Page 9 of 12
CVE-2024-48866P4MEDIUMCVSS 5.3vh5.1.0.2409vh5.1.0.2424+22 more2024-12-06
CVE-2024-48866 [MEDIUM] CWE-177 CVE-2024-48866: An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect severa
An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and later
QTS 5.2
nvd
CVE-2025-54165P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-54165 [MEDIUM] CWE-125 CVE-2025-54165: An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versio
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS hero h5.2.7.3256 b
nvd
CVE-2025-54164P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-54164 [MEDIUM] CWE-125 CVE-2025-54164: An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versio
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS hero h5.2.7.3256 b
nvd
CVE-2025-54166P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-54166 [MEDIUM] CWE-125 CVE-2025-54166: An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versio
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS hero h5.2.7.3256 b
nvd
CVE-2023-34972P4MEDIUMCVSS 6.5≥ h5.1.0, < h5.1.0.24242023-08-24
CVE-2023-34972 [MEDIUM] CWE-319 CVE-2023-34972: A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP ope
A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to read the contents of unexpected sensitive data via unspecified vectors.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2425 build 2
nvd
CVE-2018-19957P4MEDIUMCVSS 6.1fixed in h4.5.4.17712021-09-10
CVE-2018-19957 [MEDIUM] CWE-1021 CVE-2018-19957: A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS ru
A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following versions: QTS 4.5.4.1715 build 20210630 and later QuTS hero h4.5.4.1771
nvd
CVE-2026-41539P4MEDIUMCVSS 6.1vh5.2.0.2737-build_20240417vh5.2.0.2782-build_20240601+31 more2026-06-09
CVE-2026-41539 [MEDIUM] CWE-79 CVE-2026-41539: A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3492 build 20260507 and later
QuTS hero h5.2.9.3499
nvd
CVE-2024-50405P4MEDIUMCVSS 5.5vh5.2.0.2737vh5.2.0.2782+8 more2025-03-07
CVE-2024-50405 [MEDIUM] CWE-93 CVE-2024-50405: An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to a
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify application data.
We have already fixed the vulnerability in the following versions:
QTS 5.2.3.30
nvd
CVE-2023-34973P4MEDIUMCVSS 5.3≥ h5.1.0, < h5.1.0.24242023-08-24
CVE-2023-34973 [MEDIUM] CWE-331 CVE-2023-34973: An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploit
An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to predict secret via unspecified vectors.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2425 build 20230609 and later
QTS 5.1.0.2444 build 20230629 and later
QuTS hero
nvd
CVE-2024-37043P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+5 more2024-11-22
CVE-2024-37043 [MEDIUM] CWE-22 CVE-2024-37043: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read the contents of unexpected files and expose sensitive data.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 buil
nvd
CVE-2024-37046P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+5 more2024-11-22
CVE-2024-37046 [MEDIUM] CWE-22 CVE-2024-37046: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read the contents of unexpected files and expose sensitive data.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 buil
nvd
CVE-2024-53698P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+8 more2025-03-07
CVE-2024-53698 [MEDIUM] CWE-415 CVE-2024-53698: A double free vulnerability has been reported to affect several QNAP operating system versions. If e
A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.3.3006 build 20250108 and later
QuTS hero h5.2.3.3006 build 202
nvd
CVE-2023-50359P4MEDIUMCVSS 6.7vh5.1.0.2409vh5.1.0.2424+7 more2024-02-02
CVE-2023-50359 [MEDIUM] CWE-252 CVE-2023-50359: An unchecked return value vulnerability has been reported to affect several QNAP operating system ve
An unchecked return value vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated administrators to place the system in a state that could lead to a crash or other unintended behaviors via unspecified vectors.
We have already fixed the vulnerability in the fol
nvd
CVE-2020-36194P4MEDIUMCVSS 6.1fixed in h4.5.2.16382021-07-01
CVE-2020-36194 [MEDIUM] CWE-79 CVE-2020-36194: An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, t
An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.2.1566 Build 20210202. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638 build 20210414. This issue does not affect: QN
nvd
CVE-2023-23372P4MEDIUMCVSS 6.1vh5.1.0.2409vh5.0.1.2045+19 more2023-12-08
CVE-2023-23372 [MEDIUM] CWE-79 CVE-2023-23372: A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to inject malicious code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2425 build 20230609 and later
QTS 5.1.0.2444 build 20230629 and later
QTS
nvd
CVE-2021-28806P4MEDIUMCVSS 5.4fixed in h4.5.2.16382021-06-03
CVE-2021-28806 [MEDIUM] CWE-79 CVE-2021-28806: A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exp
A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.3.1652 Build 20210428. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638 Build 20210414. QNAP Systems Inc. QuT
nvd
CVE-2024-21897P4MEDIUMCVSS 5.4vh5.1.0.2409vh5.1.0.2424+8 more2024-09-06
CVE-2024-21897 [MEDIUM] CWE-79 CVE-2024-21897: A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.6.2722 build 20240402 and later
QuTS hero h5.1.6.2734 build 2
nvd
CVE-2023-45027P4MEDIUMCVSS 4.9vh5.1.0.2409vh5.1.0.2424+7 more2024-02-02
CVE-2023-45027 [MEDIUM] CWE-22 CVE-2023-45027: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116
nvd
CVE-2023-45026P4MEDIUMCVSS 4.9vh5.1.0.2409vh5.1.0.2424+7 more2024-02-02
CVE-2023-45026 [MEDIUM] CWE-22 CVE-2023-45026: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116
nvd
CVE-2025-57705P4MEDIUMCVSS 4.9vh5.2.0.2737vh5.2.0.2782+16 more2026-01-02
CVE-2025-57705 [MEDIUM] CWE-770 CVE-2025-57705: An allocation of resources without limits or throttling vulnerability has been reported to affect se
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.
We have already fixed th
nvd