Browse all 558 CVE security advisories affecting QNAP Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.
QNAP Systems Inc. manufactures network-attached storage devices and enterprise storage solutions, primarily serving small to medium-sized businesses and home users seeking centralized data management. Historically, the company’s firmware has exhibited a high volume of vulnerabilities, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within the web management interface or embedded services. Notable incidents involve critical RCE vulnerabilities that allow unauthenticated attackers to gain full system control, exposing connected data to theft or ransomware encryption. The sheer number of recorded CVEs highlights persistent challenges in secure coding practices and rigorous patch management across its diverse product line. While QNAP provides security updates, the frequency of disclosed flaws necessitates strict network segmentation and proactive monitoring for administrators relying on these storage appliances for critical infrastructure.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-62846 | QuRouter — QuRouter CWE-89 | 7.8 | - | 2026-03-20 |
| CVE-2026-22895 | QuFTP Service — QuFTP Service CWE-79 | 4.8 | - | 2026-03-20 |
| CVE-2026-22897 | QuNetSwitch — QuNetSwitch CWE-78 | 9.8 | - | 2026-03-20 |
| CVE-2026-22898 | QVR Pro — QVR Pro CWE-306 | 9.8 | - | 2026-03-20 |
| CVE-2026-22900 | QuNetSwitch — QuNetSwitch CWE-798 | 9.8 | - | 2026-03-20 |
| CVE-2026-22901 | QuNetSwitch — QuNetSwitch CWE-78 | 9.8 | - | 2026-03-20 |
| CVE-2026-22902 | QuNetSwitch — QuNetSwitch CWE-78 | 7.8 | - | 2026-03-20 |
| CVE-2025-59388 | Hyper Data Protector — Hyper Data Protector CWE-259 | 9.8AI | Critical AI | 2026-03-12 |
| CVE-2024-14026 | QTS, QuTS hero — QTS CWE-78 | 8.8AI | High AI | 2026-03-11 |
| CVE-2024-14025 | Video Station — Video Station CWE-89 | 7.2AI | High AI | 2026-03-11 |
| CVE-2024-14024 | Video Station — Video Station CWE-295 | 8.0AI | High AI | 2026-03-11 |
| CVE-2024-56807 | Media Streaming add-on — Media Streaming add-on CWE-125 | 5.5AI | Medium AI | 2026-02-11 |
| CVE-2024-56808 | Media Streaming add-on — Media Streaming add-on CWE-78 | 8.0AI | High AI | 2026-02-11 |
| CVE-2025-30266 | Qsync Central — Qsync Central CWE-476 | 7.5 | - | 2026-02-11 |
| CVE-2025-30269 | Qsync Central — Qsync Central CWE-134 | 8.2 | - | 2026-02-11 |
| CVE-2025-30276 | Qsync Central — Qsync Central CWE-787 | 9.1 | - | 2026-02-11 |
| CVE-2025-47205 | QTS, QuTS hero — QTS CWE-476 | 7.5AI | High AI | 2026-02-11 |
| CVE-2025-47209 | Qsync Central — Qsync Central CWE-476 | 7.5 | - | 2026-02-11 |
| CVE-2025-48722 | Qsync Central — Qsync Central CWE-476 | 7.5 | - | 2026-02-11 |
| CVE-2025-48723 | Qsync Central — Qsync Central CWE-120 | 9.1 | - | 2026-02-11 |
| CVE-2025-48724 | Qsync Central — Qsync Central CWE-120 | 9.1 | - | 2026-02-11 |
| CVE-2025-48725 | QuTS hero — QuTS hero CWE-120 | 8.1 | - | 2026-02-11 |
| CVE-2025-52868 | Qsync Central — Qsync Central CWE-120 | 9.1 | - | 2026-02-11 |
| CVE-2025-52869 | Qsync Central — Qsync Central CWE-120 | 9.1AI | Critical AI | 2026-02-11 |
| CVE-2025-52870 | Qsync Central — Qsync Central CWE-120 | 9.1AI | Critical AI | 2026-02-11 |
| CVE-2025-53598 | Qsync Central — Qsync Central CWE-476 | 7.5AI | High AI | 2026-02-11 |
| CVE-2025-54146 | Qsync Central — Qsync Central CWE-476 | 7.5AI | High AI | 2026-02-11 |
| CVE-2025-54147 | Qsync Central — Qsync Central CWE-476 | 7.5AI | High AI | 2026-02-11 |
| CVE-2025-54148 | Qsync Central — Qsync Central CWE-476 | 7.5AI | High AI | 2026-02-11 |
| CVE-2025-54149 | Qsync Central — Qsync Central CWE-400 | 6.2AI | Medium AI | 2026-02-11 |
This page lists every published CVE security advisory associated with QNAP Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.