VendorsQNAPqts4.3.3
Vulnerabilities

QNAP QTS 4.3.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

35CVEs
CVE-2022-27593
DeadBolt Ransomware
Published 2022-09-08 · Analyzed
10.0KEVEPSS 0.879
CVE-2021-28799
Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
Published 2021-05-13 · Analyzed
10.0KEVEPSS 0.783
CVE-2021-28809
Missing Authentication for Critical Function in RTRR Server in HBS3
Published 2021-07-08 · Modified
10.0EPSS 0.158
CVE-2018-14746
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to run arbitrary commands on the NAS.
Published 2018-11-28 · Modified
10.0EPSS 0.033
CVE-2017-7640
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
Published 2018-03-08 · Modified
10.0EPSS 0.031
CVE-2018-0721
Security Advisory for Vulnerabilities in QTS
Published 2018-11-27 · Modified
10.0EPSS 0.016
CVE-2018-0712
Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.
Published 2018-06-21 · Modified
9.8EPSS 0.026
CVE-2018-0729
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.
Published 2019-12-04 · Modified
9.8EPSS 0.023
CVE-2018-0714
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application.
Published 2018-08-13 · Modified
9.8EPSS 0.023
CVE-2018-19950
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Published 2020-11-02 · Modified
9.8EPSS 0.021
CVE-2020-36195
SQL Injection Vulnerability in Multimedia Console and the Media Streaming Add-On
Published 2021-04-17 · Modified
9.8EPSS 0.018
CVE-2018-0718
Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary commands in the compromised application.
Published 2018-09-14 · Modified
9.8EPSS 0.017
CVE-2017-13071
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.
Published 2017-11-22 · Modified
9.8EPSS 0.014
CVE-2021-38687
Stack Overflow Vulnerability in Surveillance Station
Published 2021-12-29 · Modified
9.8EPSS 0.013
CVE-2018-14749
Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could have unspecified impact on the NAS.
Published 2018-11-28 · Modified
9.8EPSS 0.012
CVE-2020-36197
Improper Access Control Vulnerability in Music Station
Published 2021-05-13 · Modified
8.8EPSS 0.185
CVE-2017-7641
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.
Published 2018-03-08 · Modified
8.8EPSS 0.005
CVE-2021-34362
Command Injection Vulnerability in Media Streaming Add-on
Published 2021-10-22 · Modified
8.7EPSS 0.013
CVE-2018-14748
Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS.
Published 2018-11-28 · Modified
7.8EPSS 0.013
CVE-2021-28807
Post-Authentication Reflected XSS Vulnerability in Q'center
Published 2021-06-03 · Modified
7.7EPSS 0.014
CVE-2018-0722
Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.
Published 2019-02-01 · Modified
7.5EPSS 0.017
CVE-2018-19952
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Published 2020-11-02 · Modified
7.5EPSS 0.013
CVE-2018-14747
NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to crash the NAS media server.
Published 2018-11-28 · Modified
7.5EPSS 0.013
CVE-2017-7638
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.
Published 2018-03-08 · Modified
6.5EPSS 0.007
CVE-2020-2491
Cross-site Scripting Vulnerability in Photo Station
Published 2020-12-10 · Modified
6.1EPSS 0.010
CVE-2017-13072
Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript code.
Published 2018-06-21 · Modified
6.1EPSS 0.008
CVE-2018-0716
Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Central 3.0.4 and earlier versions could allow remote attackers to inject Javascript code in the compromised application.
Published 2018-11-30 · Modified
6.1EPSS 0.008
CVE-2018-19951
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Published 2020-11-02 · Modified
6.1EPSS 0.008
CVE-2017-7631
Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.
Published 2018-03-27 · Modified
6.1EPSS 0.008
CVE-2017-7634
Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted link, not the normal page.
Published 2018-03-08 · Modified
6.1EPSS 0.008
CVE-2017-7632
Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.
Published 2018-03-27 · Modified
6.1EPSS 0.008
CVE-2018-19942
Cross-site Scripting Vulnerability in File Station
Published 2021-04-16 · Modified
6.1EPSS 0.007
CVE-2018-0719
Security Advisory for Vulnerabilities in QTS
Published 2018-11-27 · Modified
5.5EPSS 0.008
CVE-2017-7630
QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi.
Published 2018-03-27 · Modified
5.3EPSS 0.010
CVE-2019-7197
A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.
Published 2019-12-04 · Modified
4.8EPSS 0.012