Qnap Systems Inc Quts Hero vulnerabilities
228 known vulnerabilities affecting qnap_systems_inc/quts_hero.
Total CVEs
228
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL15HIGH107MEDIUM103LOW3
Vulnerabilities
Page 3 of 12
CVE-2026-22893P3HIGHCVSS 7.2≥ h5.2.0, < h5.2.9.3410 build 20260214≥ h5.3.0, < h5.3.4.3500 build 20260520+1 more2026-06-10
CVE-2026-22893 [HIGH] CWE-78 CVE-2026-22893: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and later
QuTS hero h5.2.9.341
nvd
CVE-2025-66279P3HIGHCVSS 7.2≥ h5.2.0, < h5.2.9.3410 build 20260214≥ h5.3.0, < h5.3.4.3500 build 20260520+1 more2026-06-10
CVE-2025-66279 [HIGH] CWE-78 CVE-2025-66279: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and later
QuTS hero h5.2.9.341
nvd
CVE-2025-66273P3HIGHCVSS 7.2≥ h5.2.0, < h5.2.9.3410 build 20260214≥ h5.3.0, < h5.3.4.3500 build 20260520+1 more2026-06-10
CVE-2025-66273 [HIGH] CWE-78 CVE-2025-66273: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and later
QuTS hero h5.2.9.341
nvd
CVE-2021-28816P3HIGHCVSS 8.8≥ unspecified, < h4.5.4.1771 build 202108252021-09-10
CVE-2021-28816 [HIGH] CWE-787 CVE-2021-28816: A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud
A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210
nvd
CVE-2025-47212P3HIGHCVSS 7.2≥ h5.2.x, < h5.2.6.3195 build 202507152025-10-03
CVE-2025-47212 [HIGH] CWE-78 CVE-2025-47212: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.6.3195 build 20250715 and later
QuTS hero h5.2.6.319
nvd
CVE-2026-24719P3HIGHCVSS 7.2≥ h5.2.0, < h5.2.9.3499 build 202605142026-06-10
CVE-2026-24719 [HIGH] CWE-78 CVE-2026-24719: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3492 build 20260507 and later
QuTS hero h5.2.9.349
nvd
CVE-2024-14026P3HIGHCVSS 7.8≥ h5.1.x, < h5.1.9.2954 build 20241120≥ h5.2.x, < h5.2.3.3006 build 202501082026-03-11
CVE-2024-14026 [HIGH] CWE-78 CVE-2024-14026: A command injection vulnerability has been reported to affect several QNAP operating system versions
A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and
nvd
CVE-2025-48725P3HIGHCVSS 8.1≥ h5.3.x, < h5.3.2.3354 build 202512252026-02-11
CVE-2025-48725 [HIGH] CWE-120 CVE-2025-48725: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following version:
QuTS hero h5.3.2.3354 build 20251225 and later
nvd
CVE-2024-50396P3HIGHCVSS 8.8≥ h5.2.x, < h5.2.1.2929 build 202410252024-11-22
CVE-2024-50396 [HIGH] CWE-134 CVE-2024-50396: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build 20241025 and later
QuTS hero h5.2.1.2
nvd
CVE-2021-44052P3HIGHCVSS 8.1≥ unspecified, < h4.5.4.1971 build 20220310≥ unspecified, < h5.0.0.1986 build 202203242022-05-05
CVE-2021-44052 [HIGH] CWE-59 CVE-2021-44052: An improper link resolution before file access ('Link Following') vulnerability has been reported to
An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed this vul
nvd
CVE-2025-30273P3HIGHCVSS 8.1≥ h5.2.x, < h5.2.5.3138 build 202505192025-08-29
CVE-2025-30273 [HIGH] CWE-787 CVE-2025-30273: An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versi
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.5.3145 build 20250526 and later
QuTS hero h5.2.5.3138 build
nvd
CVE-2025-52863P3HIGHCVSS 8.1≥ h5.2.x, < h5.2.7.3256 build 20250913≥ h5.3.x, < h5.3.0.3192 build 202507162026-01-02
CVE-2025-52863 [HIGH] CWE-120 CVE-2025-52863: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS hero h5.2.7.3256 buil
nvd
CVE-2025-52872P3HIGHCVSS 8.1≥ h5.2.x, < h5.2.7.3256 build 20250913≥ h5.3.x, < h5.3.0.3192 build 202507162026-01-02
CVE-2025-52872 [HIGH] CWE-120 CVE-2025-52872: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS hero h5.2.7.3256 buil
nvd
CVE-2025-52864P3HIGHCVSS 8.1≥ h5.2.x, < h5.2.7.3256 build 20250913≥ h5.3.x, < h5.3.0.3192 build 202507162026-01-02
CVE-2025-52864 [HIGH] CWE-120 CVE-2025-52864: A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3256 build 20250913 and later
QuTS hero h5.2.7.3256 buil
nvd
CVE-2020-2508P3HIGHCVSS 7.2fixed in h4.5.1.14722021-01-11
CVE-2020-2508 [HIGH] CWE-77 CVE-2020-2508: A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later)
nvd
CVE-2025-62847P3HIGHCVSS 7.5≥ h5.2.x, < h5.2.7.3297 build 20251024≥ h5.3.x, < h5.3.1.3292 build 202510242025-12-16
CVE-2025-62847 [HIGH] CWE-88 CVE-2025-62847: An improper neutralization of argument delimiters in a command vulnerability has been reported to af
An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3297 build 20251024 and later
QuTS hero h5.2.7.32
nvd
CVE-2025-66280P3HIGHCVSS 7.2≥ h5.2.0, < h5.2.9.3410 build 20260214≥ h5.3.0, < h5.3.4.3500 build 20260520+1 more2026-06-10
CVE-2025-66280 [HIGH] CWE-121 CVE-2025-66280: An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating s
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and
nvd
CVE-2024-27124P3HIGHCVSS 7.5≥ h5.1.x, < h5.1.3.2578 build 20231110≥ h4.5.x, < h4.5.4.2626 build 202312252024-04-26
CVE-2024-27124 [HIGH] CWE-78 CVE-2024-27124: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QTS 4.5.4.2627 build 20231225 and later
QuTS hero h5.1.
nvd
CVE-2024-21900P3MEDIUMCVSS 6.5≥ h5.1.x, < h5.1.3.2578 build 202311102024-03-08
CVE-2024-21900 [MEDIUM] CWE-74 CVE-2024-21900: An injection vulnerability has been reported to affect several QNAP operating system versions. If ex
An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QuTS hero h5.1.3.2578 build 20231110 and later
QuT
nvd
CVE-2023-34980P3HIGHCVSS 8.4≥ h4.5.x, < h4.5.4.2626 build 202312252024-03-08
CVE-2023-34980 [HIGH] CWE-78 CVE-2023-34980: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 4.5.4.2627 build 20231225 and later
QuTS hero h4.5.4.2626 build 2023
nvd