Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

QSAN — Vulnerabilities & Security Advisories 31

Browse all 31 CVE security advisories affecting QSAN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QSAN operates primarily in the network-attached storage and data management sector, providing hardware and software solutions for enterprise data protection and virtualization. Security audits reveal a concerning history of thirty-one recorded Common Vulnerabilities and Exposures, indicating persistent weaknesses in their product lifecycle management. The most prevalent vulnerability classes include remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from insufficient input validation and improper access controls within their web-based management interfaces. These defects allow attackers to potentially gain unauthorized administrative access or execute arbitrary commands on affected storage systems. While no single catastrophic public breach has been widely documented as a direct result of these specific CVEs, the high volume of disclosed issues suggests systemic gaps in secure coding practices. Organizations utilizing QSAN infrastructure must prioritize rigorous patching and network segmentation to mitigate the risk of exploitation inherent in these known defects.

CVE ID Title CVSS Severity Published
CVE-2021-37216 QSAN Storage Manager - Reflected Cross-Site Scripting — Storage Manager XN8008T CWE-79 6.1 Medium 2021-08-02
CVE-2021-32535 QSAN SANOS - Use of Hard-coded Credentials — SANOS CWE-798 9.8 Critical 2021-07-07
CVE-2021-32534 QSAN SANOS - Command Injection — SANOS CWE-78 9.8 Critical 2021-07-07
CVE-2021-32533 QSAN SANOS - Command Injection — SANOS CWE-78 9.8 Critical 2021-07-07
CVE-2021-32532 QSAN XEVO - Path Traversal — XEVO CWE-22 7.5 High 2021-07-07
CVE-2021-32531 QSAN XEVO - Command Injection Following via Init function — XEVO CWE-78 9.8 Critical 2021-07-07
CVE-2021-32530 QSAN XEVO - Command Injection Following via Array function — XEVO CWE-78 9.8 Critical 2021-07-07
CVE-2021-32529 QSAN XEVO, SANOS - Command Injection -1 — XEVO CWE-77 9.8 Critical 2021-07-07
CVE-2021-32528 QSAN Storage Manager - Exposure of Sensitive Information to an Unauthorized Actor — Storage Manager CWE-200 5.3 Medium 2021-07-07
CVE-2021-32527 QSAN Storage Manager - Path Traversal-2 — Storage Manager CWE-22 7.5 High 2021-07-07
CVE-2021-32526 QSAN Storage Manager - Incorrect Permission Assignment for Critical Resource — Storage Manager CWE-732 6.5 Medium 2021-07-07
CVE-2021-32525 QSAN Storage Manager - Use of Hard-coded Password-2 — Storage Manager CWE-259 9.1 Critical 2021-07-07
CVE-2021-32524 QSAN Storage Manager - Command Injection-3 — Storage Manager CWE-78 9.1 Critical 2021-07-07
CVE-2021-32523 QSAN Storage Manager - Improper Authorization — Storage Manager CWE-285 9.1 Critical 2021-07-07
CVE-2021-32522 QSAN Storage Manager, XEVO, SANOS - Improper Restriction of Excessive Authentication Attempts — Storage Manager CWE-307 9.8 Critical 2021-07-07
CVE-2021-32521 QSAN Storage Manager, XEVO, SANOS - Use of Hard-coded Password — Storage Manager CWE-259 7.3 High 2021-07-07
CVE-2021-32520 QSAN Storage Manager - Use of Hard-coded Cryptographic Key — Storage Manager CWE-321 9.8 Critical 2021-07-07
CVE-2021-32519 QSAN Storage Manager, XEVO, SANOS - Use of Password Hash With Insufficient Computational Effort — Storage Manager CWE-916 9.8 Critical 2021-07-07
CVE-2021-32518 QSAN Storage Manager - UNIX Symbolic Link (Symlink) Following — Storage Manager CWE-61 7.5 High 2021-07-07
CVE-2021-32517 QSAN Storage Manager - Improper Access Control — Storage Manager CWE-284 7.5 High 2021-07-07
CVE-2021-32516 QSAN Storage Manager - Path Traversal — Storage Manager CWE-22 7.5 High 2021-07-07
CVE-2021-32515 QSAN Storage Manager - Exposure of Information Through Directory Listing — Storage Manager CWE-548 5.3 Medium 2021-07-07
CVE-2021-32514 QSAN Storage Manager - Improper Access Control Following via FirwareUpgrade function — Storage Manager CWE-284 7.5 High 2021-07-07
CVE-2021-32513 QSAN Storage Manager - Command Injection Following via QsanTorture function — Storage Manager CWE-78 9.8 Critical 2021-07-07
CVE-2021-32512 QSAN Storage Manager - Command Injection Following via QuickInstall function — Storage Manager CWE-78 9.8 Critical 2021-07-07
CVE-2021-32511 QSAN Storage Manager - Exposure of Information Through Directory Listing Following via ViewBroserList function — Storage Manager CWE-548 4.3 Medium 2021-07-07
CVE-2021-32510 QSAN Storage Manager - Exposure of Information Through Directory Listing Following via Antivirus function — Storage Manager CWE-548 4.3 Medium 2021-07-07
CVE-2021-32509 QSAN Storage Manager - UNIX Symbolic Link (Symlink) Following via FileviewDoc function — Storage Manager CWE-61 6.5 Medium 2021-07-07
CVE-2021-32508 QSAN Storage Manager - UNIX Symbolic Link (Symlink) Following via FileStreaming function — Storage Manager CWE-61 6.5 Medium 2021-07-07
CVE-2021-32507 QSAN Storage Manager - Absolute Path Traversal via FileDownload function — Storage Manager CWE-36 6.5 Medium 2021-07-07

This page lists every published CVE security advisory associated with QSAN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.