QNAP Systems manufactures a widely deployed portfolio of network-attached storage (NAS) devices and associated management software serving small businesses, enterprises, and cloud environments, presenting a large and heterogeneous attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting both the native-code complexity of firmware and the privileged role of storage appliances in network infrastructure. The exposure recurs across flagship products including QTS and QuTS Hero operating systems, QSync Central, and File Station, and clusters through weakness classes including OS command injection, command injection, buffer overflows, cross-site scripting, and NULL-pointer dereferences that are characteristic of embedded systems integrating multiple protocol handlers and web interfaces. Defenders should inventory NAS devices by model and firmware version, prioritize internet-facing instances and administrative interfaces, and treat this vendor's security advisories as high-impact given the central role of storage in data availability and confidentiality. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by QNAP Systems, Inc. over time
Of all the CVEs published by QNAP Systems, Inc. as a CNA, 98.5% affect products that QNAP Systems, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by QNAP Systems, Inc., 95.0% are self-published by QNAP Systems, Inc. as a CNA.
Signals from CVEs in this vendor scope (635 CVEs).
635 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2019-7195CRITICAL This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station t | Dec 5, 2019 | 9.8 | 98 | YES | YES |
CVE-2019-7192CRITICAL This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to | Dec 5, 2019 | 9.8 | 98 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2019-7194CRITICAL This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station t | Dec 5, 2019 | 9.8 | 97 | YES | YES |
CVE-2022-27593CRITICAL An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify syst | Sep 8, 2022 | 9.1 | 96 | YES | YES |
CVE-2021-28799CRITICAL An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in | May 13, 2021 | 9.8 | 96 | YES | YES |
CVE-2023-47565HIGH An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated us | Dec 8, 2023 | 8.8 | 92 | YES | NO |
CVE-2023-47218HIGH An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via | Feb 13, 2024 | 8.3 | 88 | NO | YES |
CVE-2020-2509CRITICAL A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised ap | Apr 17, 2021 | 9.8 | 83 | YES | NO |
Signals from CVEs in this vendor scope (635 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by QNAP Systems, Inc..
Media articles that mention a CVE ID that affects a product developed by QNAP Systems, Inc. — matched by CVE ID, not by vendor name.