Qnap Systems Inc Quts Hero vulnerabilities
228 known vulnerabilities affecting qnap_systems_inc/quts_hero.
Total CVEs
228
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL15HIGH107MEDIUM103LOW3
Vulnerabilities
Page 4 of 12
CVE-2023-50363P3HIGHCVSS 8.1≥ h5.1.x, < h5.1.6.2734 build 202404142024-04-26
CVE-2023-50363 [HIGH] CWE-285 CVE-2023-50363: An incorrect authorization vulnerability has been reported to affect several QNAP operating system v
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.6.2722 build 20240402 and later
QuTS hero h5.1.6.2
nvd
CVE-2024-21902P3HIGHCVSS 8.1≥ h5.1.x, < h5.1.7.2770 build 202405202024-05-21
CVE-2024-21902 [HIGH] CWE-200 CVE-2024-21902: An incorrect permission assignment for critical resource vulnerability has been reported to affect s
An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network.
We have already fixed the vulnerability in the following version:
QTS 5.1.7.2770 build 20240520 and lat
nvd
CVE-2024-21905P3HIGHCVSS 8.2≥ h5.1.x, < h5.1.3.2578 build 202311102024-04-26
CVE-2024-21905 [HIGH] CWE-190 CVE-2024-21905: An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating s
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QuTS hero h5.1.3.2578 b
nvd
CVE-2021-34343P3HIGHCVSS 7.2≥ unspecified, < h4.5.4.1771 build 202108252021-09-10
CVE-2021-34343 [HIGH] CWE-787 CVE-2021-34343: A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud
A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210
nvd
CVE-2023-23367P3HIGHCVSS 7.2≥ h5.0.x, < h5.0.1.2376 build 202304212023-11-10
CVE-2023-23367 [HIGH] CWE-78 CVE-2023-23367: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2376 build 20230421 and later
QuTS hero h5.0.1.2376 build 2023
nvd
CVE-2023-47566P3HIGHCVSS 7.2≥ h5.1.x, < h5.1.5.2647 build 202401182024-02-02
CVE-2023-47566 [HIGH] CWE-78 CVE-2023-47566: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116 and later
QuTS hero h5.1.5.2647 build 2024
nvd
CVE-2025-9110P3HIGHCVSS 7.5≥ h5.2.x, < h5.2.8.3321 build 20251117≥ h5.3.x, < h5.3.1.3250 build 202509122026-01-02
CVE-2025-9110 [HIGH] CWE-497 CVE-2025-9110: An exposure of sensitive system information to an unauthorized control sphere vulnerability has been
An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to read application data.
We have already fixed the vulnerability in the following versions:
QTS 5.2.8.3332 build 20251128 and later
QuTS
nvd
CVE-2023-34979P3HIGHCVSS 7.2≥ h4.5.x, < h4.5.4.2790 build 202406062024-09-06
CVE-2023-34979 [HIGH] CWE-78 CVE-2023-34979: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 4.5.4.2790 build 20240605 and later
QuTS hero h4.5.4.2790 build 2024
nvd
CVE-2023-41283P3HIGHCVSS 7.2≥ h5.1.x, < h5.1.4.2596 build 202311282024-02-02
CVE-2023-41283 [HIGH] CWE-77 CVE-2023-41283: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.4.2596 build 2023
nvd
CVE-2023-41281P3HIGHCVSS 7.2≥ h5.1.x, < h5.1.4.2596 build 202311282024-02-02
CVE-2023-41281 [HIGH] CWE-77 CVE-2023-41281: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.4.2596 build 2023
nvd
CVE-2023-41282P3HIGHCVSS 7.2≥ h5.1.x, < h5.1.4.2596 build 202311282024-02-02
CVE-2023-41282 [HIGH] CWE-77 CVE-2023-41282: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.4.2596 build 2023
nvd
CVE-2024-38641P3HIGHCVSS 7.8≥ h5.1.x, < h5.1.8.2823 build 202407122024-09-06
CVE-2024-38641 [HIGH] CWE-77 CVE-2024-38641: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network users to execute commands via unspecified vectors.
We have already fixed the vulnerability in the following versions:
QTS 5.1.8.2823 build 20240712 and later
QuTS hero h5.1.8.2823 build 202
nvd
CVE-2023-23355P3HIGHCVSS 7.2≥ h5.0.*, < h5.0.1.2348 build 20230324≥ h4.5.*, < h4.5.4.2374 build 202304172023-03-29
CVE-2023-23355 [HIGH] CWE-77 CVE-2023-23355: An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploit
An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote authenticated administrators to execute commands via unspecified vectors.
QES is not affected.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2346 build 20230322 and later
QTS 4.
nvd
CVE-2023-39294P3HIGHCVSS 7.2≥ h5.1.x, < h5.1.3.2578 build 202311102024-01-05
CVE-2023-39294 [HIGH] CWE-78 CVE-2023-39294: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QuTS hero h5.1.3.2578 build 2023
nvd
CVE-2023-47567P3HIGHCVSS 7.2≥ h5.1.x, < h5.1.5.2647 build 20240118≥ h4.5.x, < h4.5.4.2626 build 202312252024-02-02
CVE-2023-47567 [HIGH] CWE-78 CVE-2023-47567: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.5.2645 build 20240116 and later
QTS 4.5.4.2627 build 20231225 an
nvd
CVE-2023-39302P3HIGHCVSS 7.2≥ h5.1.x, < h5.1.3.2578 build 202311102024-02-02
CVE-2023-39302 [HIGH] CWE-78 CVE-2023-39302: An OS command injection vulnerability has been reported to affect several QNAP operating system vers
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QTS 5.1.3.2578 build 20231110 and later
QuTS hero h5.1.3.2578 build 2023
nvd
CVE-2024-37041P3HIGHCVSS 7.2≥ h5.2.x, < h5.2.1.2929 build 202410252024-11-22
CVE-2024-37041 [HIGH] CWE-120 CVE-2024-37041: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build 20241025 and later
QuTS
nvd
CVE-2024-37044P3HIGHCVSS 7.2≥ h5.2.x, < h5.2.1.2929 build 202410252024-11-22
CVE-2024-37044 [HIGH] CWE-120 CVE-2024-37044: A buffer copy without checking size of input vulnerability has been reported to affect several QNAP
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build 20241025 and later
QuTS
nvd
CVE-2024-50398P3HIGHCVSS 7.2≥ h5.2.x, < h5.2.1.2929 build 202410252024-11-22
CVE-2024-50398 [HIGH] CWE-134 CVE-2024-50398: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build
nvd
CVE-2024-50399P3HIGHCVSS 7.2≥ h5.2.x, < h5.2.1.2929 build 202410252024-11-22
CVE-2024-50399 [HIGH] CWE-134 CVE-2024-50399: A use of externally-controlled format string vulnerability has been reported to affect several QNAP
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build
nvd