Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

QNAP Systems Inc. — Vulnerabilities & Security Advisories 558

Browse all 558 CVE security advisories affecting QNAP Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QNAP Systems Inc. manufactures network-attached storage devices and enterprise storage solutions, primarily serving small to medium-sized businesses and home users seeking centralized data management. Historically, the company’s firmware has exhibited a high volume of vulnerabilities, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within the web management interface or embedded services. Notable incidents involve critical RCE vulnerabilities that allow unauthenticated attackers to gain full system control, exposing connected data to theft or ransomware encryption. The sheer number of recorded CVEs highlights persistent challenges in secure coding practices and rigorous patch management across its diverse product line. While QNAP provides security updates, the frequency of disclosed flaws necessitates strict network segmentation and proactive monitoring for administrators relying on these storage appliances for critical infrastructure.

CVE ID Title CVSS Severity Published
CVE-2022-27595 QVPN Device Client — QVPN Windows CWE-427 7.8 High 2024-12-19
CVE-2022-27600 QTS, QuTS hero, QuTScloud — QTS CWE-400 6.8 Medium 2024-12-19
CVE-2023-23354 QuLog Center — QuLog Center CWE-79 7.3 High 2024-12-19
CVE-2023-23356 QuFirewall — QuFirewall CWE-77 5.5 Medium 2024-12-19
CVE-2023-23357 QuLog Center — QuLog Center CWE-79 4.8 Medium 2024-12-19
CVE-2024-48863 License Center — License Center CWE-78 8.8 - 2024-12-06
CVE-2024-50403 QTS, QuTS hero — QTS CWE-134 6.5 - 2024-12-06
CVE-2024-50402 QTS, QuTS hero — QTS CWE-134 6.5 - 2024-12-06
CVE-2024-50393 QTS, QuTS hero — QTS CWE-78 7.2 - 2024-12-06
CVE-2024-48868 QTS, QuTS hero — QTS CWE-93 5.3 - 2024-12-06
CVE-2024-48867 QTS, QuTS hero — QTS CWE-93 5.3 - 2024-12-06
CVE-2024-48866 QTS, QuTS hero — QTS CWE-177 7.5 - 2024-12-06
CVE-2024-48865 QTS, QuTS hero — QTS CWE-295 9.8 - 2024-12-06
CVE-2024-48859 QTS, QuTS hero — QTS CWE-287 9.8 - 2024-12-06
CVE-2024-50404 Qsync Central — Qsync Central CWE-59 5.7 - 2024-12-06
CVE-2024-50389 QuRouter — QuRouter CWE-89 9.8 - 2024-12-06
CVE-2024-50387 SMB Service — SMB Service CWE-89 9.8 - 2024-12-06
CVE-2024-50388 HBS 3 Hybrid Backup Sync — HBS 3 Hybrid Backup Sync CWE-77 9.8 - 2024-12-06
CVE-2024-53691 QTS, QuTS hero — QTS CWE-59 5.7 - 2024-12-06
CVE-2024-32767 Photo Station — Photo Station CWE-79 6.3 Medium 2024-11-22
CVE-2024-32768 Photo Station — Photo Station CWE-79 6.3 Medium 2024-11-22
CVE-2024-32769 Photo Station — Photo Station CWE-79 6.3 Medium 2024-11-22
CVE-2024-32770 Photo Station — Photo Station CWE-79 6.3 Medium 2024-11-22
CVE-2024-37041 QTS, QuTS hero — QTS CWE-120 7.2 - 2024-11-22
CVE-2024-37042 QTS, QuTS hero — QTS CWE-476 4.9 - 2024-11-22
CVE-2024-37043 QTS, QuTS hero — QTS CWE-22 4.9 - 2024-11-22
CVE-2024-37044 QTS, QuTS hero — QTS CWE-120 7.2 - 2024-11-22
CVE-2024-37045 QTS, QuTS hero — QTS CWE-476 4.9 - 2024-11-22
CVE-2024-37046 QTS, QuTS hero — QTS CWE-22 4.9 - 2024-11-22
CVE-2024-37047 QTS, QuTS hero — QTS CWE-120 7.2 - 2024-11-22

This page lists every published CVE security advisory associated with QNAP Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.