QNAP QuTS hero

Our sources currently list 247 known vulnerabilities affecting QNAP QuTS hero. 16 are rated critical severity. 2 of 247 are actively exploited according to CISA, the most recent added 11 April 2022.

Last updated: 22 July 2026, 20:44 AEST

No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.

Known vulnerabilities in QNAP QuTS hero, highest risk first.Showing the 50 highest-risk of 247 total.
CVESeverityExploitationPublishedSummary
CVE-2021-28799Critical (10.0)Actively exploited · ransomwareAn improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in …
CVE-2020-2509Critical (9.8)Actively exploitedA command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised ap…
CVE-2023-47218Medium (5.8)Elevated likelihood (90%)An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via …
CVE-2023-51364High (8.7)Elevated likelihood (42%)A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpec…
CVE-2024-27130High (7.2)Elevated likelihood (38%)A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to …
CVE-2023-51365High (8.7)Elevated likelihood (35%)A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpec…
CVE-2024-21899Critical (9.8)Elevated likelihood (24%)An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the sec…
CVE-2024-53691High (8.8)Elevated likelihood (20%)A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user…
CVE-2023-23368Critical (9.8)Elevated likelihood (19%)An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via …
CVE-2020-36197High (7.1)Elevated likelihood (18%)An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attackers to compromise the security…
CVE-2023-50358Medium (5.8)Elevated likelihood (14%)An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via …
CVE-2024-21900Medium (4.3)No exploitation reportedAn injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands v…
CVE-2019-7198Critical (9.8)No exploitation reportedThis command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versio…
CVE-2022-27596Critical (9.8)No exploitation reportedA vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already f…
CVE-2020-25847High (8.8)No exploitation reportedThis command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versio…
CVE-2024-32766Critical (10.0)No exploitation reportedAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via …
CVE-2021-34343Medium (6.0)No exploitation reportedA stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitr…
CVE-2020-2508High (7.2)No exploitation reportedA command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised ap…
CVE-2021-28802Critical (9.8)No exploitation reportedA command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised…
CVE-2021-28804Critical (9.8)No exploitation reportedA command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised…
CVE-2021-28815Medium (6.0)No exploitation reportedInsecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive …
CVE-2021-44051High (8.8)No exploitation reportedA command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitra…
CVE-2021-34344Critical (9.8)No exploitation reportedA stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulnerability allows attackers to execute arbitrary code. We have…
CVE-2023-39296High (7.5)No exploitation reportedA prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attri…
CVE-2021-28812High (8.8)No exploitation reportedA command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary comma…
CVE-2023-23367Medium (4.7)No exploitation reportedAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators t…
CVE-2021-44052Medium (6.5)No exploitation reportedAn improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vu…
CVE-2024-27124High (7.5)No exploitation reportedAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via …
CVE-2023-39297High (8.8)No exploitation reportedAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute…
CVE-2021-28807High (7.7)No exploitation reportedA post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject maliciou…
CVE-2025-47212High (7.2)No exploitation reportedA command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the…
CVE-2024-50393Critical (9.8)No exploitation reportedA command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitr…
CVE-2021-34362High (8.7)No exploitation reportedA command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary c…
CVE-2023-23355Medium (6.6)No exploitation reportedAn OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote authenticated administrators to exe…
CVE-2023-23362High (8.8)No exploitation reportedAn OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via …
CVE-2024-21898High (8.8)No exploitation reportedAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute…
CVE-2023-47566Medium (6.7)No exploitation reportedAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators t…
CVE-2023-45025Critical (9.0)No exploitation reportedAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via …
CVE-2023-39294Medium (6.6)No exploitation reportedAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators t…
CVE-2023-47567Medium (4.7)No exploitation reportedAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators t…
CVE-2023-34979Medium (6.6)No exploitation reportedAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators t…
CVE-2023-39302Medium (6.6)No exploitation reportedAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators t…
CVE-2025-66273High (7.2)No exploitation reportedA command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the…
CVE-2025-66279High (7.2)No exploitation reportedA command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the…
CVE-2020-2495Medium (6.1)No exploitation reportedIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the fo…
CVE-2020-2496Medium (6.1)No exploitation reportedIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the fo…
CVE-2026-22893High (7.2)No exploitation reportedA command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the…
CVE-2020-2494Medium (6.1)No exploitation reportedThis cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of M…
CVE-2026-24719High (7.2)No exploitation reportedA command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the…
CVE-2020-2497Medium (6.1)No exploitation reportedIf exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities…

Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.

Let's talk

2 of these are being actively exploited right now.

Our Newcastle team can audit your QNAP estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.