QNAP QTS

Our sources currently list 320 known vulnerabilities affecting QNAP QTS. 54 are rated critical severity. 12 of 320 are actively exploited according to CISA, the most recent added 8 September 2022.

Last updated: 22 July 2026, 20:44 AEST

No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.

Known vulnerabilities in QNAP QTS, highest risk first.Showing the 50 highest-risk of 320 total.
CVESeverityExploitationPublishedSummary
CVE-2014-6271Critical (9.8)Actively exploitedGNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra…
CVE-2014-7169Critical (9.8)Actively exploitedGNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri…
CVE-2019-7195Critical (9.8)Actively exploited · ransomwareThis external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station t…
CVE-2019-7192Critical (9.8)Actively exploited · ransomwareThis improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to…
CVE-2022-27593Critical (10.0)Actively exploited · ransomwareAn externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify syst…
CVE-2019-7194Critical (9.8)Actively exploited · ransomwareThis external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station t…
CVE-2021-28799Critical (10.0)Actively exploited · ransomwareAn improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in …
CVE-2020-2509Critical (9.8)Actively exploitedA command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised ap…
CVE-2018-19949Critical (9.8)Actively exploited · ransomwareIf exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2…
CVE-2018-19953Medium (6.1)Actively exploited · ransomwareIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4…
CVE-2018-19943High (8.0)Actively exploited · ransomwareIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS …
CVE-2019-7193Critical (9.8)Actively exploited · ransomwareThis improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest v…
CVE-2023-47218Medium (5.8)Elevated likelihood (90%)An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via …
CVE-2017-6360Critical (9.8)Elevated likelihood (66%)QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
CVE-2017-6361Critical (9.8)Elevated likelihood (57%)QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
CVE-2023-51364High (8.7)Elevated likelihood (42%)A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpec…
CVE-2024-27130High (7.2)Elevated likelihood (38%)A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to …
CVE-2023-51365High (8.7)Elevated likelihood (35%)A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpec…
CVE-2017-6359Critical (9.8)Elevated likelihood (27%)QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
CVE-2024-21899Critical (9.8)Elevated likelihood (24%)An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the sec…
CVE-2024-53691High (8.8)Elevated likelihood (20%)A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user…
CVE-2023-23368Critical (9.8)Elevated likelihood (19%)An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via …
CVE-2024-21901Medium (4.7)Elevated likelihood (19%)A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a netwo…
CVE-2020-36197High (7.1)Elevated likelihood (18%)An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attackers to compromise the security…
CVE-2017-13067Critical (9.8)Elevated likelihood (17%)QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This par…
CVE-2021-28809Critical (9.8)Elevated likelihood (16%)An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security …
CVE-2023-23369Critical (9.0)Elevated likelihood (15%)An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via …
CVE-2023-50358Medium (5.8)Elevated likelihood (14%)An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via …
CVE-2024-21900Medium (4.3)No exploitation reportedAn injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands v…
CVE-2017-5227High (7.5)No exploitation reportedQNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux…
CVE-2017-17033Critical (9.8)No exploitation reportedA buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow…
CVE-2015-6003Critical (9.3)No exploitation reportedDirectory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitr…
CVE-2018-14746Critical (9.8)No exploitation reportedCommand Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote at…
CVE-2017-7876Critical (10.0)No exploitation reportedThis command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517…
CVE-2017-17028Critical (9.8)No exploitation reportedA buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier coul…
CVE-2017-17027Critical (9.8)No exploitation reportedA buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remot…
CVE-2017-17029Critical (9.8)No exploitation reportedA buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow re…
CVE-2017-17030Critical (9.8)No exploitation reportedA buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow re…
CVE-2017-17031Critical (9.8)No exploitation reportedA buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow…
CVE-2017-17032Critical (9.8)No exploitation reportedA buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow…
CVE-2019-7198Critical (9.8)No exploitation reportedThis command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versio…
CVE-2022-27596Critical (9.8)No exploitation reportedA vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already f…
CVE-2018-0712Critical (9.8)No exploitation reportedCommand injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote at…
CVE-2020-25847High (8.8)No exploitation reportedThis command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versio…
CVE-2018-0729Critical (9.8)No exploitation reportedThis command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station t…
CVE-2017-10700Critical (9.8)No exploitation reportedIn the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.
CVE-2017-7640Critical (9.8)No exploitation reportedQNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
CVE-2024-32766Critical (10.0)No exploitation reportedAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via …
CVE-2018-0714Critical (9.8)No exploitation reportedCommand injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versi…
CVE-2020-2490High (7.2)No exploitation reportedIf exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421…

Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.

Let's talk

12 of these are being actively exploited right now.

Our Newcastle team can audit your QNAP estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.