Osnexus develops QuantaStor, a storage-management platform for virtualized and cloud environments that presents a web-facing administrative interface vulnerable to application-layer flaws. Its vulnerability profile recurs through input-handling and privilege-management weaknesses including cross-site scripting, command injection, OS command injection, and information disclosure, typical of web-administered appliances where sanitization gaps expose both the management tier and potentially underlying system access. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Osnexus over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-10880CRITICAL OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowi | Jun 4, 2026 | 9.8 | 39 | NO | NO |
CVE-2017-9979MEDIUM On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. T | Aug 28, 2017 | 6.1 | 30 | NO | YES |
CVE-2017-9978MEDIUM On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could | Aug 28, 2017 | 5.3 | 28 | NO | YES |
CVE-2021-4406HIGH An authenticated attacker is able to create alerts that trigger a stored XSS attack.
POC
* go to the alert manager
* open the ITSM tab
* add a webhook with the URL/se | Jul 10, 2023 | 7.2 | 24 | NO | NO |
CVE-2021-42082HIGH Local users are able to execute scripts under root privileges.
POC
On the local host run the following command:
curl 'localhost:8154/qstor/qs_upgrade.py?taskId=1&a=;`whoami`' | Jul 10, 2023 | 7.8 | 23 | NO | NO |
CVE-2021-42081HIGH An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API.
POC
http://<IP_ADDRESS>/qstorapi/storageSystemModify?storageSystem=&newName=qua | Jul 10, 2023 | 7.2 | 22 | NO | NO |
CVE-2021-42080HIGH An attacker is able to launch a Reflected XSS attack using a crafted URL.
POC:
Visit the following URL
https://<IPADDRESS>:8153/qstorapi/echo?inputMessage=<img%20src=x%20onerror= | Jul 10, 2023 | 7.4 | 22 | NO | NO |
CVE-2021-42083MEDIUM An authenticated attacker is able to create alerts that trigger a stored XSS attack.
POC
* go to the alert manager
* open the ITSM tab
* add a webhook with the URL/se | Jul 10, 2023 | 5.4 | 18 | NO | NO |
CVE-2021-42079MEDIUM An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests.
POC
Step 1: Prepare the SSRF with a req | Jul 10, 2023 | 4.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Osnexus.
Media articles that mention a CVE ID that affects a product developed by Osnexus — matched by CVE ID, not by vendor name.