« Volver al listado

Qnap

Qnap QTS: vulnerabilidades y CVE

Qnap QTS tiene 283 vulnerabilidades publicadas, 71 de ellas en los últimos 12 meses. 39 son críticas y 7 figuran en el catálogo de explotación activa de CISA.

CVE283
Últimos 12 meses71
Críticas39
Explotadas activamente7

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2019-7193Crítica (9.8)14%⚠ Explotación activa5 dic 2019
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
CVE-2018-19943Media (5.4)21%⚠ Explotación activa28 oct 2020
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS…
CVE-2018-19953Media (6.1)29%⚠ Explotación activa28 oct 2020
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS…
CVE-2018-19949Crítica (9.8)28%⚠ Explotación activa28 oct 2020
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201…
CVE-2020-2509Crítica (9.8)34%⚠ Explotación activa17 abr 2021
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this…
CVE-2014-7169Crítica (9.8)100%⚠ Explotación activa25 sept 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown…
CVE-2014-6271Crítica (9.8)100%⚠ Explotación activa24 sept 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-24719Media (6.1)0.98%—10 jun 2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary…
CVE-2026-24717Baja (1.2)0.39%—10 jun 2026
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of…
CVE-2026-24716Baja (1.2)0.33%—10 jun 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a…
CVE-2026-22893Alta (8.6)1.1%—10 jun 2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary…
CVE-2025-66281Media (6.9)0.46%—10 jun 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-66280Media (5.1)0.44%—10 jun 2026
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to…
CVE-2025-66279Alta (8.6)1.1%—10 jun 2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary…
CVE-2025-66273Alta (8.6)1.1%—10 jun 2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary…
CVE-2025-66276Crítica (9.2)0.29%—10 jun 2026
QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later
CVE-2025-62858Media (5.1)0.45%—9 jun 2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash…
CVE-2026-41539Media (6.3)0.33%—9 jun 2026
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application…
CVE-2024-14026Baja (2)0.62%—11 mar 2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the…
CVE-2025-66277Crítica (9.2)0.67%—11 feb 2026
A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have…
CVE-2025-58466Baja (1.2)0.53%—11 feb 2026
A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to denial of…
CVE-2025-48725Baja (0.6)0.42%—11 feb 2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.…
CVE-2025-47205Media (5.1)0.44%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a…
CVE-2025-9110Baja (2.7)0.45%—2 ene 2026
An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to…
CVE-2025-62852Baja (1.2)0.36%—2 ene 2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash…
CVE-2025-59381Media (6.9)0.47%—2 ene 2026
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of…
CVE-2025-59380Media (4.6)0.58%—2 ene 2026
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of…
CVE-2025-48721Baja (1.2)0.43%—2 ene 2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash…
CVE-2025-57705Media (4.6)0.36%—2 ene 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the…
CVE-2025-54166Media (4.6)0.34%—2 ene 2026
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.…
CVE-2025-54165Media (4.6)0.34%—2 ene 2026
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.…
CVE-2025-54164Media (4.6)0.34%—2 ene 2026
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.…
CVE-2025-53596Baja (1.2)0.36%—2 ene 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a…
CVE-2025-53593Baja (1.2)0.36%—2 ene 2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash…
CVE-2025-53592Baja (1.3)0.34%—2 ene 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a…
CVE-2025-53591Baja (1.2)0.34%—2 ene 2026
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability…
CVE-2025-53590Baja (1.2)0.36%—2 ene 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application5
  2. T1059 Command and Scripting Interpreter4
  3. T1059.007 JavaScript3
  4. T1189 Drive-by Compromise2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qnap