Qnap Systems Inc Quts Hero vulnerabilities
228 known vulnerabilities affecting qnap_systems_inc/quts_hero.
Total CVEs
228
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL15HIGH107MEDIUM103LOW3
Vulnerabilities
Page 10 of 12
CVE-2023-45027P4MEDIUMCVSS 4.9≥ h5.1.x, < h5.1.5.2647 build 202401182024-02-02
CVE-2023-45027 [MEDIUM] CWE-22 CVE-2023-45027: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116
nvd
CVE-2023-45026P4MEDIUMCVSS 4.9≥ h5.1.x, < h5.1.5.2647 build 202401182024-02-02
CVE-2023-45026 [MEDIUM] CWE-22 CVE-2023-45026: A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116
nvd
CVE-2024-53696P4MEDIUMCVSS 4.9≥ h4.5.x, < h4.5.4.2956 build 202411192025-03-07
CVE-2024-53696 [MEDIUM] CWE-918 CVE-2024-53696: A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If expl
A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data.
We have already fixed the vulnerability in the following versions:
QuLog Center 1.7.0.829 ( 2024/10/01 ) and later
QuLog Center 1.8.0
nvd
CVE-2020-2495P4MEDIUMCVSS 6.1fixed in h4.5.1.14722020-12-10
CVE-2020-2495 [MEDIUM] CWE-79 CVE-2020-2495: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.
nvd
CVE-2020-2496P4MEDIUMCVSS 6.1fixed in h4.5.1.14722020-12-10
CVE-2020-2496 [MEDIUM] CWE-79 CVE-2020-2496: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.
nvd
CVE-2020-2497P4MEDIUMCVSS 6.1fixed in h4.5.1.14722020-12-10
CVE-2020-2497 [MEDIUM] CWE-79 CVE-2020-2497: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and late
nvd
CVE-2020-2498P4MEDIUMCVSS 6.1fixed in h4.5.1.14722020-12-10
CVE-2020-2498 [MEDIUM] CWE-79 CVE-2020-2498: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicio
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and l
nvd
CVE-2025-47205P4MEDIUMCVSS 4.9≥ h5.2.x, < h5.2.8.3321 build 202511172026-02-11
CVE-2025-47205 [MEDIUM] CWE-476 CVE-2025-47205: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.8.3332 build 20251128 and lat
nvd
CVE-2025-66274P4MEDIUMCVSS 4.9≥ h5.2.0, < h5.2.9.3410 build 20260214≥ h5.3.0, < h5.3.2.3354 build 20251225+1 more2026-02-11
CVE-2025-66274 [MEDIUM] CWE-476 CVE-2025-66274: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and lat
nvd
CVE-2025-53589P4MEDIUMCVSS 4.9≥ h5.2.x, < h5.2.7.3256 build 20250913≥ h5.3.x, < h5.3.1.3250 build 202509122026-01-02
CVE-2025-53589 [MEDIUM] CWE-476 CVE-2025-53589: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-53405P4MEDIUMCVSS 4.9≥ h5.2.x, < h5.2.7.3256 build 20250913≥ h5.3.x, < h5.3.1.3250 build 202509122026-01-02
CVE-2025-53405 [MEDIUM] CWE-476 CVE-2025-53405: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-52426P4MEDIUMCVSS 4.9≥ h5.2.x, < h5.2.7.3256 build 20250913≥ h5.3.x, < h5.3.1.3250 build 202509122026-01-02
CVE-2025-52426 [MEDIUM] CWE-476 CVE-2025-52426: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-53414P4MEDIUMCVSS 4.9≥ h5.2.x, < h5.2.7.3256 build 20250913≥ h5.3.x, < h5.3.1.3250 build 202509122026-01-02
CVE-2025-53414 [MEDIUM] CWE-476 CVE-2025-53414: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-53596P4MEDIUMCVSS 4.9≥ h5.2.x, < h5.2.7.3256 build 20250913≥ h5.3.x, < h5.3.1.3250 build 202509122026-01-02
CVE-2025-53596 [MEDIUM] CWE-476 CVE-2025-53596: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-52430P4MEDIUMCVSS 4.9≥ h5.2.x, < h5.2.7.3256 build 20250913≥ h5.3.x, < h5.3.1.3250 build 202509122026-01-02
CVE-2025-52430 [MEDIUM] CWE-476 CVE-2025-52430: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-52431P4MEDIUMCVSS 4.9≥ h5.2.x, < h5.2.7.3256 build 20250913≥ h5.3.x, < h5.3.1.3250 build 202509122026-01-02
CVE-2025-52431 [MEDIUM] CWE-476 CVE-2025-52431: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and lat
nvd
CVE-2025-47213P4MEDIUMCVSS 4.9≥ h5.2.x, < h5.2.6.3195 build 202507152025-10-03
CVE-2025-47213 [MEDIUM] CWE-476 CVE-2025-47213: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-48726P4MEDIUMCVSS 4.9≥ h5.2.x, < h5.2.6.3195 build 202507152025-10-03
CVE-2025-48726 [MEDIUM] CWE-476 CVE-2025-48726: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-48728P4MEDIUMCVSS 4.9≥ h5.2.x, < h5.2.6.3195 build 202507152025-10-03
CVE-2025-48728 [MEDIUM] CWE-476 CVE-2025-48728: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.6.3195 build 20250715 and lat
nvd
CVE-2025-48729P4MEDIUMCVSS 4.9≥ h5.2.x, < h5.2.6.3195 build 202507152025-10-03
CVE-2025-48729 [MEDIUM] CWE-476 CVE-2025-48729: A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.6.3195 build 20250715 and lat
nvd