Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

QNAP Systems, Inc.

First CVE: Sep 21, 2009Active for: 17 yearsTotal CVEs: 635
59.3
VTI Score
TOP TARGET

QNAP Systems manufactures a widely deployed portfolio of network-attached storage (NAS) devices and associated management software serving small businesses, enterprises, and cloud environments, presenting a large and heterogeneous attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting both the native-code complexity of firmware and the privileged role of storage appliances in network infrastructure. The exposure recurs across flagship products including QTS and QuTS Hero operating systems, QSync Central, and File Station, and clusters through weakness classes including OS command injection, command injection, buffer overflows, cross-site scripting, and NULL-pointer dereferences that are characteristic of embedded systems integrating multiple protocol handlers and web interfaces. Defenders should inventory NAS devices by model and firmware version, prioritize internet-facing instances and administrative interfaces, and treat this vendor's security advisories as high-impact given the central role of storage in data availability and confidentiality. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
635
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
2.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by QNAP Systems, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2009
16 years ago
Most Recent CVE
Jun 10, 2026
44 days ago

Self-Reporting Analysis

Of all the CVEs published by QNAP Systems, Inc. as a CNA, 98.5% affect products that QNAP Systems, Inc. develops as a vendor.

98.5%
Self-reported: 603 (98.5%)
Third-party: 9 (1.5%)

Of all the CVEs published that affect products developed by QNAP Systems, Inc., 95.0% are self-published by QNAP Systems, Inc. as a CNA.

95.0%
Self-published: 603 (95.0%)
Other CNAs: 32 (5.0%)

Products(143 total)

Top CVEs

Signals from CVEs in this vendor scope (635 CVEs).

635 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-6271CRITICAL
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
CVE-2019-7195CRITICAL
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station t
Dec 5, 20199.898YESYES
CVE-2019-7192CRITICAL
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to
Dec 5, 20199.898YESYES
CVE-2014-7169CRITICAL
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri
Sep 25, 20149.898YESYES
CVE-2019-7194CRITICAL
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station t
Dec 5, 20199.897YESYES
CVE-2022-27593CRITICAL
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify syst
Sep 8, 20229.196YESYES
CVE-2021-28799CRITICAL
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in
May 13, 20219.896YESYES
CVE-2023-47565HIGH
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated us
Dec 8, 20238.892YESNO
CVE-2023-47218HIGH
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via
Feb 13, 20248.388NOYES
CVE-2020-2509CRITICAL
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised ap
Apr 17, 20219.883YESNO
View all 635 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products635 CVEs
46%
36%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local40 (6.3%)
Network577 (90.9%)
Unknown9 (1.4%)
Physical2 (0.3%)
Adjacent Network7 (1.1%)
Attack Complexity
Low620 (97.6%)
High6 (0.9%)
Unknown9 (1.4%)
User Interaction
None535 (84.3%)
Unknown9 (1.4%)
Required91 (14.3%)
Privileges Required
Low218 (34.3%)
High183 (28.8%)
None225 (35.4%)
Unknown9 (1.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (635 CVEs).

CISA KEV
14 CVEs
2.2% of CVEs· 99th percentile
Metasploit
8 CVEs
1.3% of CVEs· 97th percentile
Nuclei
8 CVEs
1.3% of CVEs· 95th percentile
ExploitDB
15 CVEs
2.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by QNAP Systems, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by QNAP Systems, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For QNAP Systems, Inc.'s Products

View all 6 CNAs →

Top CWEs