Qsan develops a focused line of network-attached storage systems and associated management software, including the Storage Manager, SanOS operating system, and XEvo appliances, serving as centralized data repositories in enterprise and small-business environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrating in command-injection, path-traversal, hard-coded credential, and directory-enumeration weaknesses that are characteristic of embedded storage management interfaces exposed to network access. These weakness classes reflect the authentication and input-handling demands of administrative control planes that, when compromised, grant direct access to stored data and system configuration. Defenders should prioritize Qsan storage appliances for network segmentation and access control, treat management interfaces as high-value targets, and monitor vendor advisories closely given the severity profile; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qsan over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-37216MEDIUM QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access | Aug 2, 2021 | 6.1 | 31 | NO | YES |
CVE-2021-32534CRITICAL QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The | Jul 7, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-32531CRITICAL OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The referred vulnerability has been solv | Jul 7, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-32522CRITICAL Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain acces | Jul 7, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-32535CRITICAL The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions. The | Jul 7, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-32530CRITICAL OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status parameter. The referred vulnerabi | Jul 7, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-32529CRITICAL Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations | Jul 7, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-32520CRITICAL Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and re | Jul 7, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-32533CRITICAL The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referr | Jul 7, 2021 | 9.8 | 28 | NO | NO |
CVE-2021-32513CRITICAL QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred | Jul 7, 2021 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qsan.
Media articles that mention a CVE ID that affects a product developed by Qsan — matched by CVE ID, not by vendor name.