Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Qsan

First CVE: Jul 7, 2021Active for: 5 yearsTotal CVEs: 31
48.7
VTI Score
High

Qsan develops a focused line of network-attached storage systems and associated management software, including the Storage Manager, SanOS operating system, and XEvo appliances, serving as centralized data repositories in enterprise and small-business environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrating in command-injection, path-traversal, hard-coded credential, and directory-enumeration weaknesses that are characteristic of embedded storage management interfaces exposed to network access. These weakness classes reflect the authentication and input-handling demands of administrative control planes that, when compromised, grant direct access to stored data and system configuration. Defenders should prioritize Qsan storage appliances for network segmentation and access control, treat management interfaces as high-value targets, and monitor vendor advisories closely given the severity profile; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
4.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Qsan over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2021
5 years ago
Most Recent CVE
Aug 2, 2021
1,817 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-37216MEDIUM
QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access
Aug 2, 20216.131NOYES
CVE-2021-32534CRITICAL
QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The
Jul 7, 20219.831NONO
CVE-2021-32531CRITICAL
OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The referred vulnerability has been solv
Jul 7, 20219.831NONO
CVE-2021-32522CRITICAL
Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain acces
Jul 7, 20219.831NONO
CVE-2021-32535CRITICAL
The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions. The
Jul 7, 20219.829NONO
CVE-2021-32530CRITICAL
OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status parameter. The referred vulnerabi
Jul 7, 20219.829NONO
CVE-2021-32529CRITICAL
Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations
Jul 7, 20219.829NONO
CVE-2021-32520CRITICAL
Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and re
Jul 7, 20219.829NONO
CVE-2021-32533CRITICAL
The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referr
Jul 7, 20219.828NONO
CVE-2021-32513CRITICAL
QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred
Jul 7, 20219.828NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
32%
32%
35%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network31 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None30 (96.8%)
Unknown0 (0.0%)
Required1 (3.2%)
Privileges Required
Low7 (22.6%)
High3 (9.7%)
None21 (67.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.2% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Qsan.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Qsan — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Qsan's Products

View all 1 CNAs →

Top CWEs