Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

QNAP Systems Inc. — Vulnerabilities & Security Advisories 558

Browse all 558 CVE security advisories affecting QNAP Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QNAP Systems Inc. manufactures network-attached storage devices and enterprise storage solutions, primarily serving small to medium-sized businesses and home users seeking centralized data management. Historically, the company’s firmware has exhibited a high volume of vulnerabilities, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within the web management interface or embedded services. Notable incidents involve critical RCE vulnerabilities that allow unauthenticated attackers to gain full system control, exposing connected data to theft or ransomware encryption. The sheer number of recorded CVEs highlights persistent challenges in secure coding practices and rigorous patch management across its diverse product line. While QNAP provides security updates, the frequency of disclosed flaws necessitates strict network segmentation and proactive monitoring for administrators relying on these storage appliances for critical infrastructure.

CVE ID Title CVSS Severity Published
CVE-2021-38684 Buffer Overflow Vulnerability in Multimedia Console — Multimedia Console CWE-787 8.1 High 2021-11-13
CVE-2021-34357 Reflected XSS Vulnerability in QmailAgent — QmailAgent CWE-79 6.9 Medium 2021-11-13
CVE-2021-34362 Command Injection Vulnerability in Media Streaming Add-on — Media Streaming add-on CWE-78 8.7 High 2021-10-22
CVE-2021-38675 Stored XSS Vulnerability in Image2PDF — Image2PDF CWE-79 5.4 Medium 2021-10-01
CVE-2021-34356 Stored XSS Vulnerability in Photo Station — Photo Station CWE-79 7.6 High 2021-10-01
CVE-2021-34355 Stored XSS Vulnerability in Photo Station — Photo Station CWE-79 7.6 High 2021-10-01
CVE-2021-34354 Stored Cross-site Scripting Vulnerability in Photo Station — Photo Station CWE-79 7.6 High 2021-10-01
CVE-2021-34352 Command Injection Vulnerability in QVR — QVR CWE-78 7.2 High 2021-10-01
CVE-2021-34351 Command Injection Vulnerability in QVR — QVR CWE-78 9.8 Critical 2021-09-27
CVE-2021-34349 Command Injection Vulnerability in QVR — QVR CWE-78 7.2 High 2021-09-27
CVE-2021-34348 Command Injection Vulnerability in QVR — QVR CWE-78 9.8 Critical 2021-09-27
CVE-2021-34346 Stack Based Overflow Vulnerability in NVR Storage Expansion — NVR Storage Expansion CWE-787 9.8 Critical 2021-09-10
CVE-2021-34345 Stack Based Overflow Vulnerability in NVR Storage Expansion — NVR Storage Expansion CWE-787 9.8 Critical 2021-09-10
CVE-2021-34344 Stack Buffer Overflow Vulnerability in QUSBCam2 — QUSBCam2 CWE-787 9.8 Critical 2021-09-10
CVE-2021-34343 Buffer Overflow Vulnerability in QTS, QuTS hero, and QuTScloud — QTS CWE-787 6.0 Medium 2021-09-10
CVE-2021-28816 Stack Buffer Overflow Vulnerabilities in QTS, QuTS hero, and QuTScloud — QTS CWE-787 7.6 High 2021-09-10
CVE-2021-28813 Insufficiently Protected Credentials Vulnerability in QSW-M2116P-2T2S and QuNetSwitch — QSW-M2116P-2T2S CWE-259 9.6 Critical 2021-09-10
CVE-2018-19957 Insufficient HTTP Security Headers in QTS, QuTS hero, and QuTScloud — QTS CWE-1021 6.1 - 2021-09-10
CVE-2021-28809 Missing Authentication for Critical Function in RTRR Server in HBS3 — HBS 3 CWE-284 9.8 Critical 2021-07-08
CVE-2021-28804 Command Injection Vulnerabilities in QTS and QuTS hero — QTS CWE-78 9.8 - 2021-07-01
CVE-2021-28803 Stored XSS Vulnerability in Q'center — Q'center CWE-80 8.5 - 2021-07-01
CVE-2021-28802 Command Injection Vulnerabilities in QTS and QuTS hero — QTS CWE-78 9.8 - 2021-07-01
CVE-2020-36196 Stored XSS Vulnerability in QuLog Center — QuLog Center CWE-80 5.4 - 2021-07-01
CVE-2020-36194 XSS Vulnerability in QTS and QuTS heroCommand Injection Vulnerabilities in QTS and QuTS hero — QTS CWE-79 6.1 Medium 2021-07-01
CVE-2021-28800 Command Injection Vulnerability in QTS — QTS CWE-78 8.1 High 2021-06-24
CVE-2021-28815 Insecure Storage of Sensitive Information in myQNAPcloud Link — myQNAPcloud Link CWE-922 6.0 Medium 2021-06-16
CVE-2021-28814 Improper Access Control Vulnerability in Helpdesk — Helpdesk CWE-269 8.8 High 2021-06-11
CVE-2021-28805 Inclusion of Sensitive Information in QSS — QSS CWE-540 7.8 High 2021-06-11
CVE-2021-28801 Out-of-Bounds Read Vulnerability in QSS — QSS CWE-125 3.1 Low 2021-06-11
CVE-2021-28812 Command Injection Vulnerability in Video Station — Video Station CWE-1286 8.8 High 2021-06-03

This page lists every published CVE security advisory associated with QNAP Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.