VendorsQNAPqtsall versions
Vulnerabilities

QNAP QTS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

320CVEs
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Published 2014-09-24 · Analyzed
10.0KEV21 PoCEPSS 1.000
CVE-2014-7169
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
Published 2014-09-25 · Analyzed
10.0KEV15 PoCEPSS 0.999
CVE-2022-27593
DeadBolt Ransomware
Published 2022-09-08 · Analyzed
10.0KEVEPSS 0.879
CVE-2021-28799
Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
Published 2021-05-13 · Analyzed
10.0KEVEPSS 0.783
CVE-2017-6360
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
Published 2017-03-23 · Modified
10.01 PoCEPSS 0.661
CVE-2017-6361
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
Published 2017-03-23 · Modified
10.01 PoCEPSS 0.568
CVE-2017-6359
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
Published 2017-03-23 · Modified
10.01 PoCEPSS 0.269
CVE-2021-28809
Missing Authentication for Critical Function in RTRR Server in HBS3
Published 2021-07-08 · Modified
10.0EPSS 0.158
CVE-2019-7193
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
Published 2019-12-05 · Analyzed
10.0KEVEPSS 0.144
CVE-2017-7876
This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and later versions.
Published 2017-06-15 · Modified
10.0EPSS 0.033
CVE-2018-14746
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to run arbitrary commands on the NAS.
Published 2018-11-28 · Modified
10.0EPSS 0.033
CVE-2017-7640
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
Published 2018-03-08 · Modified
10.0EPSS 0.031
CVE-2017-10700
In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.
Published 2017-09-19 · Modified
10.0EPSS 0.023
CVE-2024-32766
QTS, QuTS hero, QuTScloud
Published 2024-04-26 · Analyzed
10.0EPSS 0.023
CVE-2018-0721
Security Advisory for Vulnerabilities in QTS
Published 2018-11-27 · Modified
10.0EPSS 0.016
CVE-2019-7195
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Published 2019-12-05 · Analyzed
9.8KEVEPSS 0.897
CVE-2019-7192
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
Published 2019-12-05 · Analyzed
9.8KEVEPSS 0.881
CVE-2019-7194
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Published 2019-12-05 · Analyzed
9.8KEVEPSS 0.831
CVE-2020-2509
Command Injection Vulnerability in QTS and QuTS hero
Published 2021-04-17 · Analyzed
9.8KEVEPSS 0.334
CVE-2018-19949
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
Published 2020-10-28 · Analyzed
9.8KEVEPSS 0.244
CVE-2024-21899
QTS, QuTS hero, QuTScloud
Published 2024-03-08 · Modified
9.8EPSS 0.244
CVE-2023-23368
QTS, QuTS hero, QuTScloud
Published 2023-11-03 · Modified
9.8EPSS 0.188
CVE-2017-13067
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerability allows a remote attacker to execute commands on a QNAP NAS using a transcoding service on port 9251. A remote user does not require any privileges to successfully execute an attack.
Published 2017-09-14 · Modified
9.8EPSS 0.167
CVE-2023-23369
QTS, Multimedia Console, and Media Streaming add-on
Published 2023-11-03 · Modified
9.8EPSS 0.145
CVE-2017-17033
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.044
CVE-2017-17028
A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.033
CVE-2017-17030
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.033
CVE-2017-17029
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.033
CVE-2017-17031
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.033
CVE-2017-17032
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.033
CVE-2017-17027
A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Published 2017-12-21 · Modified
9.8EPSS 0.033
CVE-2019-7198
Command Injection Vulnerability in QTS and QuTS hero
Published 2020-12-10 · Modified
9.8EPSS 0.027
CVE-2022-27596
Vulnerability in QTS
Published 2023-01-30 · Modified
9.8EPSS 0.027
CVE-2018-0712
Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.
Published 2018-06-21 · Modified
9.8EPSS 0.026
CVE-2018-0729
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.
Published 2019-12-04 · Modified
9.8EPSS 0.023
CVE-2018-0714
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application.
Published 2018-08-13 · Modified
9.8EPSS 0.023
CVE-2018-19950
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Published 2020-11-02 · Modified
9.8EPSS 0.021
CVE-2018-0730
This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
Published 2019-12-04 · Modified
9.8EPSS 0.020
CVE-2021-28804
Command Injection Vulnerabilities in QTS and QuTS hero
Published 2021-07-01 · Modified
9.8EPSS 0.018
CVE-2021-28802
Command Injection Vulnerabilities in QTS and QuTS hero
Published 2021-07-01 · Modified
9.8EPSS 0.018
1 / 8Next →