VendorsQNAPqts4.2.6
Vulnerabilities

QNAP QTS 4.2.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

35CVEs
CVE-2022-27593
DeadBolt Ransomware
Published 2022-09-08 · Analyzed
10.0KEVEPSS 0.879
CVE-2018-14746
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to run arbitrary commands on the NAS.
Published 2018-11-28 · Modified
10.0EPSS 0.033
CVE-2018-0721
Security Advisory for Vulnerabilities in QTS
Published 2018-11-27 · Modified
10.0EPSS 0.016
CVE-2019-7195
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Published 2019-12-05 · Analyzed
9.8KEVEPSS 0.897
CVE-2019-7192
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
Published 2019-12-05 · Analyzed
9.8KEVEPSS 0.881
CVE-2019-7194
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Published 2019-12-05 · Analyzed
9.8KEVEPSS 0.831
CVE-2020-2509
Command Injection Vulnerability in QTS and QuTS hero
Published 2021-04-17 · Analyzed
9.8KEVEPSS 0.340
CVE-2018-19949
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
Published 2020-10-28 · Analyzed
9.8KEVEPSS 0.284
CVE-2023-23369
QTS, Multimedia Console, and Media Streaming add-on
Published 2023-11-03 · Modified
9.8EPSS 0.145
CVE-2018-0712
Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.
Published 2018-06-21 · Modified
9.8EPSS 0.026
CVE-2018-0729
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.
Published 2019-12-04 · Modified
9.8EPSS 0.023
CVE-2018-0714
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application.
Published 2018-08-13 · Modified
9.8EPSS 0.023
CVE-2018-0730
This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
Published 2019-12-04 · Modified
9.8EPSS 0.020
CVE-2019-7183
This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.
Published 2019-12-05 · Modified
9.8EPSS 0.016
CVE-2018-14749
Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could have unspecified impact on the NAS.
Published 2018-11-28 · Modified
9.8EPSS 0.012
CVE-2021-44051
Command injection
Published 2022-05-05 · Modified
8.8EPSS 0.017
CVE-2021-44052
Arbitrary file read
Published 2022-05-05 · Modified
8.1EPSS 0.016
CVE-2018-19943
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later
Published 2020-10-28 · Analyzed
8.0KEVEPSS 0.215
CVE-2018-14748
Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS.
Published 2018-11-28 · Modified
7.8EPSS 0.013
CVE-2018-0722
Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.
Published 2019-02-01 · Modified
7.5EPSS 0.017
CVE-2018-14747
NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to crash the NAS media server.
Published 2018-11-28 · Modified
7.5EPSS 0.013
CVE-2023-39300
QTS
Published 2024-09-06 · Analyzed
7.2EPSS 0.012
CVE-2018-19953
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
Published 2020-10-28 · Analyzed
6.1KEVEPSS 0.288
CVE-2020-2491
Cross-site Scripting Vulnerability in Photo Station
Published 2020-12-10 · Modified
6.1EPSS 0.010
CVE-2017-13072
Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript code.
Published 2018-06-21 · Modified
6.1EPSS 0.008
CVE-2018-0716
Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Central 3.0.4 and earlier versions could allow remote attackers to inject Javascript code in the compromised application.
Published 2018-11-30 · Modified
6.1EPSS 0.008
CVE-2017-7631
Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.
Published 2018-03-27 · Modified
6.1EPSS 0.008
CVE-2017-7632
Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.
Published 2018-03-27 · Modified
6.1EPSS 0.008
CVE-2021-44053
Reflected XSS
Published 2022-05-05 · Modified
6.1EPSS 0.008
CVE-2018-19942
Cross-site Scripting Vulnerability in File Station
Published 2021-04-16 · Modified
6.1EPSS 0.007
CVE-2021-44054
Open redirect
Published 2022-05-05 · Modified
6.1EPSS 0.006
CVE-2023-50358
QTS, QuTS hero, QuTScloud
Published 2024-02-13 · Analyzed
5.8EPSS 0.135
CVE-2018-0719
Security Advisory for Vulnerabilities in QTS
Published 2018-11-27 · Modified
5.5EPSS 0.008
CVE-2017-7630
QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi.
Published 2018-03-27 · Modified
5.3EPSS 0.010
CVE-2019-7197
A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.
Published 2019-12-04 · Modified
4.8EPSS 0.012