Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

QNAP Systems Inc. — Vulnerabilities & Security Advisories 558

Browse all 558 CVE security advisories affecting QNAP Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QNAP Systems Inc. manufactures network-attached storage devices and enterprise storage solutions, primarily serving small to medium-sized businesses and home users seeking centralized data management. Historically, the company’s firmware has exhibited a high volume of vulnerabilities, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within the web management interface or embedded services. Notable incidents involve critical RCE vulnerabilities that allow unauthenticated attackers to gain full system control, exposing connected data to theft or ransomware encryption. The sheer number of recorded CVEs highlights persistent challenges in secure coding practices and rigorous patch management across its diverse product line. While QNAP provides security updates, the frequency of disclosed flaws necessitates strict network segmentation and proactive monitoring for administrators relying on these storage appliances for critical infrastructure.

Found 234 results / 558 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2020-36194 XSS Vulnerability in QTS and QuTS heroCommand Injection Vulnerabilities in QTS and QuTS hero — QTS CWE-79 6.1 Medium 2021-07-01
CVE-2021-28800 Command Injection Vulnerability in QTS — QTS CWE-78 8.1 High 2021-06-24
CVE-2021-28806 DOM-Based XSS Vulnerability in QTS and QuTS hero — QTS CWE-79 5.7 Medium 2021-06-03
CVE-2021-28798 Relative Path Traversal Vulnerability in QTS and QuTS hero — QTS CWE-284 8.8 High 2021-05-21
CVE-2020-2509 Command Injection Vulnerability in QTS and QuTS hero — QTS CWE-77 9.8 - 2021-04-17
CVE-2020-36195 SQL Injection Vulnerability in Multimedia Console and the Media Streaming Add-On — QTS CWE-20 9.8 Critical 2021-04-17
CVE-2018-19942 Cross-site Scripting Vulnerability in File Station — QTS CWE-79 6.1 - 2021-04-16
CVE-2020-2508 Command Injection Vulnerability in QTS and QuTS hero — QTS CWE-77 7.2 High 2021-01-11
CVE-2018-19941 Cleartext Storage of Sensitive Information in Cookies — QTS CWE-315 7.5 - 2020-12-31
CVE-2018-19944 Cleartext Transmission of Sensitive Information in SNMP — QTS CWE-311 7.5 - 2020-12-31
CVE-2018-19945 Improper Limitation of a Pathname to a Restricted Directory in QTS — QTS CWE-20 7.5 - 2020-12-31
CVE-2020-25847 Command Injection Vulnerability in QTS and QuTS hero — QTS CWE-77 8.8 High 2020-12-29
CVE-2020-2498 Cross-site scripting vulnerability in QTS and QuTS hero — QTS CWE-79 6.1 - 2020-12-10
CVE-2020-2497 Cross-site scripting vulnerability in QTS and QuTS hero — QTS CWE-79 6.1 - 2020-12-10
CVE-2020-2496 Cross-site scripting vulnerability in QTS and QuTS hero — QTS CWE-79 6.1 - 2020-12-10
CVE-2020-2495 Cross-site scripting vulnerability in QTS and QuTS hero — QTS CWE-79 6.1 - 2020-12-10
CVE-2019-7198 Command Injection Vulnerability in QTS and QuTS hero — QTS CWE-77 9.8 - 2020-12-10
CVE-2020-2490 QNAP Systems QNAP QTS 命令注入漏洞 — QTS CWE-77 7.2 High 2020-11-16
CVE-2020-2492 QNAP Systems QNAP QTS 命令注入漏洞 — QTS CWE-77 7.2 High 2020-11-16
CVE-2018-19943 QNAP Systems TS-870 跨站脚本漏洞 — QTS CWE-79 8.0 High 2020-10-28
CVE-2018-19949 QNAP Systems TS-870 命令注入漏洞 — QTS CWE-20 9.8 - 2020-10-28
CVE-2018-19953 QNAP Systems TS-870 跨站脚本漏洞 — QTS CWE-79 6.1 - 2020-10-28
CVE-2018-0721 Security Advisory for Vulnerabilities in QTS — QTS CWE-120 7.7 High 2018-11-27
CVE-2018-0719 Security Advisory for Vulnerabilities in QTS — QTS CWE-79 5.5 Medium 2018-11-27

This page lists every published CVE security advisory associated with QNAP Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.