Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

QNAP Systems Inc. — Vulnerabilities & Security Advisories 558

Browse all 558 CVE security advisories affecting QNAP Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QNAP Systems Inc. manufactures network-attached storage devices and enterprise storage solutions, primarily serving small to medium-sized businesses and home users seeking centralized data management. Historically, the company’s firmware has exhibited a high volume of vulnerabilities, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within the web management interface or embedded services. Notable incidents involve critical RCE vulnerabilities that allow unauthenticated attackers to gain full system control, exposing connected data to theft or ransomware encryption. The sheer number of recorded CVEs highlights persistent challenges in secure coding practices and rigorous patch management across its diverse product line. While QNAP provides security updates, the frequency of disclosed flaws necessitates strict network segmentation and proactive monitoring for administrators relying on these storage appliances for critical infrastructure.

CVE ID Title CVSS Severity Published
CVE-2025-44012 Qsync Central — Qsync Central CWE-770 5.8 - 2025-10-03
CVE-2025-44011 Qsync Central — Qsync Central CWE-476 7.5 - 2025-10-03
CVE-2025-44010 Qsync Central — Qsync Central CWE-476 7.5 - 2025-10-03
CVE-2025-44009 Qsync Central — Qsync Central CWE-476 7.5 - 2025-10-03
CVE-2025-44008 Qsync Central — Qsync Central CWE-476 7.5 - 2025-10-03
CVE-2025-44007 Qsync Central — Qsync Central CWE-770 5.8 - 2025-10-03
CVE-2025-44006 Qsync Central — Qsync Central CWE-770 5.8 - 2025-10-03
CVE-2025-33040 Qsync Central — Qsync Central CWE-770 5.8 - 2025-10-03
CVE-2025-33039 Qsync Central — Qsync Central CWE-770 5.8 - 2025-10-03
CVE-2025-33034 Qsync Central — Qsync Central CWE-22 7.5 - 2025-10-03
CVE-2024-56804 Video Station — Video Station CWE-89 9.8 - 2025-10-03
CVE-2025-52861 VioStor — VioStor CWE-22 6.5 - 2025-08-29
CVE-2025-52856 VioStor — VioStor CWE-287 9.8 - 2025-08-29
CVE-2025-44015 HybridDesk Station — HybridDesk Station CWE-77 8.0 - 2025-08-29
CVE-2025-33038 Qsync Central — Qsync Central CWE-22 7.5 - 2025-08-29
CVE-2025-33037 Qsync Central — Qsync Central CWE-22 7.5 - 2025-08-29
CVE-2025-33036 Qsync Central — Qsync Central CWE-22 7.5 - 2025-08-29
CVE-2025-33033 Qsync Central — Qsync Central CWE-22 7.5 - 2025-08-29
CVE-2025-33032 QTS, QuTS hero — QTS CWE-22 4.9 - 2025-08-29
CVE-2025-30278 Qsync Central — Qsync Central CWE-295 7.4 - 2025-08-29
CVE-2025-30277 Qsync Central — Qsync Central CWE-295 7.4 - 2025-08-29
CVE-2025-30275 Qsync Central — Qsync Central CWE-476 7.5 - 2025-08-29
CVE-2025-30274 QTS, QuTS hero — QTS CWE-476 7.5 - 2025-08-29
CVE-2025-30273 QTS, QuTS hero — QTS CWE-787 9.1 - 2025-08-29
CVE-2025-30272 QTS, QuTS hero — QTS CWE-476 7.5 - 2025-08-29
CVE-2025-30271 QTS, QuTS hero — QTS CWE-22 6.5 - 2025-08-29
CVE-2025-30270 QTS, QuTS hero — QTS CWE-22 6.5 - 2025-08-29
CVE-2025-30268 QTS, QuTS hero — QTS CWE-476 7.5 - 2025-08-29
CVE-2025-30267 QTS, QuTS hero — QTS CWE-476 7.5 - 2025-08-29
CVE-2025-30265 QTS, QuTS hero — QTS CWE-120 8.1 - 2025-08-29

This page lists every published CVE security advisory associated with QNAP Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.