Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

QNAP Systems Inc. — Vulnerabilities & Security Advisories 558

Browse all 558 CVE security advisories affecting QNAP Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QNAP Systems Inc. manufactures network-attached storage devices and enterprise storage solutions, primarily serving small to medium-sized businesses and home users seeking centralized data management. Historically, the company’s firmware has exhibited a high volume of vulnerabilities, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within the web management interface or embedded services. Notable incidents involve critical RCE vulnerabilities that allow unauthenticated attackers to gain full system control, exposing connected data to theft or ransomware encryption. The sheer number of recorded CVEs highlights persistent challenges in secure coding practices and rigorous patch management across its diverse product line. While QNAP provides security updates, the frequency of disclosed flaws necessitates strict network segmentation and proactive monitoring for administrators relying on these storage appliances for critical infrastructure.

CVE ID Title CVSS Severity Published
CVE-2022-27597 QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) — QTS CWE-1295 2.7 Low 2023-03-29
CVE-2022-27598 QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) — QTS CWE-125 2.7 Low 2023-03-29
CVE-2022-27596 Vulnerability in QTS — QuTS hero CWE-89 9.8 Critical 2023-01-30
CVE-2022-27593 DeadBolt Ransomware — Photo Station CWE-610 10.0 Critical 2022-09-08
CVE-2021-34360 CSRF Bypass in Proxy Server — Proxy Server CWE-352 5.3 Medium 2022-05-26
CVE-2022-27588 Vulnerability in QVR — QVR CWE-77 9.8 Critical 2022-05-05
CVE-2021-44057 Improper authentication in Photo Station — Photo Station CWE-287 7.1 High 2022-05-05
CVE-2021-44056 Improper authentication in Video Station — Video Station CWE-287 7.1 High 2022-05-05
CVE-2021-44055 Information leakage in Video Station — Video Station CWE-862 5.3 Medium 2022-05-05
CVE-2021-44054 Open redirect — QuTScloud CWE-601 4.3 Medium 2022-05-05
CVE-2021-44053 Reflected XSS — QTS CWE-79 5.7 Medium 2022-05-05
CVE-2021-44052 Arbitrary file read — QuTScloud CWE-59 6.5 Medium 2022-05-05
CVE-2021-44051 Command injection — QuTScloud CWE-77 8.8 High 2022-05-05
CVE-2021-38693 Path Traversal in thttpd — QuTScloud CWE-22 5.3 Medium 2022-05-05
CVE-2021-34361 Reflected XSS Vulnerability in Proxy Server — Proxy Server CWE-79 5.3 Medium 2022-02-25
CVE-2021-34359 Stored XSS Vulnerability in Proxy Server — Proxy Server CWE-79 6.9 Medium 2022-02-25
CVE-2021-38679 Improper Authentication in Kazoo Server — Kazoo Server CWE-287 6.5 Medium 2022-02-11
CVE-2021-38692 Stack Overflow Vulnerability in QVR Elite, QVR Pro and QVR Guard — QVR Elite CWE-120 8.1 High 2022-01-14
CVE-2021-38691 Stack Overflow Vulnerability in QVR Elite, QVR Pro and QVR Guard — QVR Elite CWE-120 8.1 High 2022-01-14
CVE-2021-38690 Stack Overflow Vulnerability in QVR Elite, QVR Pro and QVR Guard — QVR Elite CWE-120 8.1 High 2022-01-14
CVE-2021-38689 Stack Overflow Vulnerability in QVR Elite, QVR Pro and QVR Guard — QVR Elite CWE-120 8.1 High 2022-01-14
CVE-2021-38682 Stack Overflow Vulnerability in QVR Elite, QVR Pro and QVR Guard — QVR Elite CWE-120 8.1 High 2022-01-14
CVE-2021-38678 Open Redirect Vulnerability in QcalAgent — QcalAgent CWE-601 6.1 Medium 2022-01-14
CVE-2021-38677 Reflected XSS Vulnerability in QcalAgent — QcalAgent CWE-79 5.3 Medium 2022-01-14
CVE-2021-38674 Reflected XSS Vulnerability in TFTP — QuTS hero CWE-79 4.2 Medium 2022-01-07
CVE-2021-38688 Improper Authentication in Qfile — Qfile CWE-287 7.1 High 2021-12-29
CVE-2021-38687 Stack Overflow Vulnerability in Surveillance Station — Surveillance Station CWE-120 8.1 High 2021-12-29
CVE-2021-38686 Improper Authentication Vulnerability in VioStor — QVR CWE-287 8.8 High 2021-11-26
CVE-2021-38685 Command Injection Vulnerability in VioStor — QVR CWE-78 9.8 Critical 2021-11-26
CVE-2021-34358 CSRF Vulnerability in QmailAgent — QmailAgent CWE-352 6.8 Medium 2021-11-20

This page lists every published CVE security advisory associated with QNAP Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.