Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

QNAP Systems Inc. — Vulnerabilities & Security Advisories 558

Browse all 558 CVE security advisories affecting QNAP Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QNAP Systems Inc. manufactures network-attached storage devices and enterprise storage solutions, primarily serving small to medium-sized businesses and home users seeking centralized data management. Historically, the company’s firmware has exhibited a high volume of vulnerabilities, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within the web management interface or embedded services. Notable incidents involve critical RCE vulnerabilities that allow unauthenticated attackers to gain full system control, exposing connected data to theft or ransomware encryption. The sheer number of recorded CVEs highlights persistent challenges in secure coding practices and rigorous patch management across its diverse product line. While QNAP provides security updates, the frequency of disclosed flaws necessitates strict network segmentation and proactive monitoring for administrators relying on these storage appliances for critical infrastructure.

CVE ID Title CVSS Severity Published
CVE-2024-37048 QTS, QuTS hero — QTS CWE-476 4.9 - 2024-11-22
CVE-2024-37049 QTS, QuTS hero — QTS CWE-120 7.2 - 2024-11-22
CVE-2024-37050 QTS, QuTS hero — QTS CWE-120 7.2 - 2024-11-22
CVE-2024-38643 Notes Station 3 — Notes Station 3 CWE-306 9.8 - 2024-11-22
CVE-2024-38644 Notes Station 3 — Notes Station 3 CWE-77 8.8 - 2024-11-22
CVE-2024-38645 Notes Station 3 — Notes Station 3 CWE-918 6.5 - 2024-11-22
CVE-2024-38646 Notes Station 3 — Notes Station 3 CWE-732 5.1 - 2024-11-22
CVE-2024-38647 QNAP AI Core — QNAP AI Core CWE-540 9.1 - 2024-11-22
CVE-2024-48860 QHora — QuRouter CWE-77 9.8 - 2024-11-22
CVE-2024-48861 QHora — QuRouter CWE-77 7.8 - 2024-11-22
CVE-2024-48862 QuLog Center — QuLog Center CWE-59 9.1 - 2024-11-22
CVE-2024-50395 Media Streaming add-on — Media Streaming add-on CWE-639 7.8 - 2024-11-22
CVE-2024-50396 QTS, QuTS hero — QTS CWE-134 9.1 - 2024-11-22
CVE-2024-50397 QTS, QuTS hero — QTS CWE-134 8.1 - 2024-11-22
CVE-2024-50398 QTS, QuTS hero — QTS CWE-134 6.5 - 2024-11-22
CVE-2024-50399 QTS, QuTS hero — QTS CWE-134 6.5 - 2024-11-22
CVE-2024-50400 QTS, QuTS hero — QTS CWE-134 6.5 - 2024-11-22
CVE-2024-50401 QTS, QuTS hero — QTS CWE-134 6.5 - 2024-11-22
CVE-2024-38640 Download Station — Download Station CWE-79 5.4 - 2024-09-06
CVE-2024-38642 QuMagie — QuMagie CWE-295 7.8 - 2024-09-06
CVE-2024-38641 QTS, QuTS hero — QTS CWE-77 8.0 - 2024-09-06
CVE-2024-32763 QTS, QuTS hero — QTS CWE-120 8.8 - 2024-09-06
CVE-2024-21906 QTS, QuTS hero — QTS CWE-78 4.7 Medium 2024-09-06
CVE-2023-34979 QTS, QuTS hero — QTS CWE-78 6.6 Medium 2024-09-06
CVE-2023-34974 QTS, QuTS hero, QuTScloud, QVR, QES — QTS CWE-78 8.8 High 2024-09-06
CVE-2024-32762 QuLog Center — QuLog Center CWE-79 8.2 High 2024-09-06
CVE-2024-27125 Helpdesk — Helpdesk CWE-79 3.5 Low 2024-09-06
CVE-2024-32771 QTS, QuTS hero — QTS CWE-307 2.6 Low 2024-09-06
CVE-2023-39298 QTS, QuTS hero — QTS CWE-862 7.8 High 2024-09-06
CVE-2023-39300 QTS — QTS CWE-78 7.2 High 2024-09-06

This page lists every published CVE security advisory associated with QNAP Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.