QNAP QuTS hero
Our sources currently list 247 known vulnerabilities affecting QNAP QuTS hero. 16 are rated critical severity. 2 of 247 are actively exploited according to CISA, the most recent added 11 April 2022.
Last updated: 22 July 2026, 20:44 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2021-28799 | Critical (10.0) | Actively exploited · ransomware | An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in … | |
| CVE-2020-2509 | Critical (9.8) | Actively exploited | A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised ap… | |
| CVE-2023-47218 | Medium (5.8) | Elevated likelihood (90%) | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via … | |
| CVE-2023-51364 | High (8.7) | Elevated likelihood (42%) | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpec… | |
| CVE-2024-27130 | High (7.2) | Elevated likelihood (38%) | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to … | |
| CVE-2023-51365 | High (8.7) | Elevated likelihood (35%) | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpec… | |
| CVE-2024-21899 | Critical (9.8) | Elevated likelihood (24%) | An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the sec… | |
| CVE-2024-53691 | High (8.8) | Elevated likelihood (20%) | A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user… | |
| CVE-2023-23368 | Critical (9.8) | Elevated likelihood (19%) | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via … | |
| CVE-2020-36197 | High (7.1) | Elevated likelihood (18%) | An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attackers to compromise the security… | |
| CVE-2023-50358 | Medium (5.8) | Elevated likelihood (14%) | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via … | |
| CVE-2024-21900 | Medium (4.3) | No exploitation reported | An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands v… | |
| CVE-2019-7198 | Critical (9.8) | No exploitation reported | This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versio… | |
| CVE-2022-27596 | Critical (9.8) | No exploitation reported | A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already f… | |
| CVE-2020-25847 | High (8.8) | No exploitation reported | This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versio… | |
| CVE-2024-32766 | Critical (10.0) | No exploitation reported | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via … | |
| CVE-2021-34343 | Medium (6.0) | No exploitation reported | A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitr… | |
| CVE-2020-2508 | High (7.2) | No exploitation reported | A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised ap… | |
| CVE-2021-28802 | Critical (9.8) | No exploitation reported | A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised… | |
| CVE-2021-28804 | Critical (9.8) | No exploitation reported | A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised… | |
| CVE-2021-28815 | Medium (6.0) | No exploitation reported | Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive … | |
| CVE-2021-44051 | High (8.8) | No exploitation reported | A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitra… | |
| CVE-2021-34344 | Critical (9.8) | No exploitation reported | A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulnerability allows attackers to execute arbitrary code. We have… | |
| CVE-2023-39296 | High (7.5) | No exploitation reported | A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attri… | |
| CVE-2021-28812 | High (8.8) | No exploitation reported | A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary comma… | |
| CVE-2023-23367 | Medium (4.7) | No exploitation reported | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators t… | |
| CVE-2021-44052 | Medium (6.5) | No exploitation reported | An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vu… | |
| CVE-2024-27124 | High (7.5) | No exploitation reported | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via … | |
| CVE-2023-39297 | High (8.8) | No exploitation reported | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute… | |
| CVE-2021-28807 | High (7.7) | No exploitation reported | A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject maliciou… | |
| CVE-2025-47212 | High (7.2) | No exploitation reported | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the… | |
| CVE-2024-50393 | Critical (9.8) | No exploitation reported | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitr… | |
| CVE-2021-34362 | High (8.7) | No exploitation reported | A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary c… | |
| CVE-2023-23355 | Medium (6.6) | No exploitation reported | An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote authenticated administrators to exe… | |
| CVE-2023-23362 | High (8.8) | No exploitation reported | An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via … | |
| CVE-2024-21898 | High (8.8) | No exploitation reported | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute… | |
| CVE-2023-47566 | Medium (6.7) | No exploitation reported | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators t… | |
| CVE-2023-45025 | Critical (9.0) | No exploitation reported | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via … | |
| CVE-2023-39294 | Medium (6.6) | No exploitation reported | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators t… | |
| CVE-2023-47567 | Medium (4.7) | No exploitation reported | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators t… | |
| CVE-2023-34979 | Medium (6.6) | No exploitation reported | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators t… | |
| CVE-2023-39302 | Medium (6.6) | No exploitation reported | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators t… | |
| CVE-2025-66273 | High (7.2) | No exploitation reported | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the… | |
| CVE-2025-66279 | High (7.2) | No exploitation reported | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the… | |
| CVE-2020-2495 | Medium (6.1) | No exploitation reported | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the fo… | |
| CVE-2020-2496 | Medium (6.1) | No exploitation reported | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the fo… | |
| CVE-2026-22893 | High (7.2) | No exploitation reported | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the… | |
| CVE-2020-2494 | Medium (6.1) | No exploitation reported | This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of M… | |
| CVE-2026-24719 | High (7.2) | No exploitation reported | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the… | |
| CVE-2020-2497 | Medium (6.1) | No exploitation reported | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities… |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
2 of these are being actively exploited right now.
Our Newcastle team can audit your QNAP estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
