Qnap
Qnap QTS: vulnerabilidades y CVE
Qnap QTS tiene 283 vulnerabilidades publicadas, 71 de ellas en los últimos 12 meses. 39 son críticas y 7 figuran en el catálogo de explotación activa de CISA.
CVE283
Últimos 12 meses71
Críticas39
Explotadas activamente7
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-7193 | Crítica (9.8) | 14% | ⚠ Explotación activa | 5 dic 2019 | This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions. |
| CVE-2018-19943 | Media (5.4) | 21% | ⚠ Explotación activa | 28 oct 2020 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS… |
| CVE-2018-19953 | Media (6.1) | 29% | ⚠ Explotación activa | 28 oct 2020 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS… |
| CVE-2018-19949 | Crítica (9.8) | 28% | ⚠ Explotación activa | 28 oct 2020 | If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201… |
| CVE-2020-2509 | Crítica (9.8) | 34% | ⚠ Explotación activa | 17 abr 2021 | A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this… |
| CVE-2014-7169 | Crítica (9.8) | 100% | ⚠ Explotación activa | 25 sept 2014 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown… |
| CVE-2014-6271 | Crítica (9.8) | 100% | ⚠ Explotación activa | 24 sept 2014 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-24719 | Media (6.1) | 0.98% | — | 10 jun 2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary… |
| CVE-2026-24717 | Baja (1.2) | 0.39% | — | 10 jun 2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of… |
| CVE-2026-24716 | Baja (1.2) | 0.33% | — | 10 jun 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a… |
| CVE-2026-22893 | Alta (8.6) | 1.1% | — | 10 jun 2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary… |
| CVE-2025-66281 | Media (6.9) | 0.46% | — | 10 jun 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-66280 | Media (5.1) | 0.44% | — | 10 jun 2026 | An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to… |
| CVE-2025-66279 | Alta (8.6) | 1.1% | — | 10 jun 2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary… |
| CVE-2025-66273 | Alta (8.6) | 1.1% | — | 10 jun 2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary… |
| CVE-2025-66276 | Crítica (9.2) | 0.29% | — | 10 jun 2026 | QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later |
| CVE-2025-62858 | Media (5.1) | 0.45% | — | 9 jun 2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash… |
| CVE-2026-41539 | Media (6.3) | 0.33% | — | 9 jun 2026 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application… |
| CVE-2024-14026 | Baja (2) | 0.62% | — | 11 mar 2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the… |
| CVE-2025-66277 | Crítica (9.2) | 0.67% | — | 11 feb 2026 | A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have… |
| CVE-2025-58466 | Baja (1.2) | 0.53% | — | 11 feb 2026 | A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to denial of… |
| CVE-2025-48725 | Baja (0.6) | 0.42% | — | 11 feb 2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.… |
| CVE-2025-47205 | Media (5.1) | 0.44% | — | 11 feb 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a… |
| CVE-2025-9110 | Baja (2.7) | 0.45% | — | 2 ene 2026 | An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to… |
| CVE-2025-62852 | Baja (1.2) | 0.36% | — | 2 ene 2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash… |
| CVE-2025-59381 | Media (6.9) | 0.47% | — | 2 ene 2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of… |
| CVE-2025-59380 | Media (4.6) | 0.58% | — | 2 ene 2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of… |
| CVE-2025-48721 | Baja (1.2) | 0.43% | — | 2 ene 2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash… |
| CVE-2025-57705 | Media (4.6) | 0.36% | — | 2 ene 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the… |
| CVE-2025-54166 | Media (4.6) | 0.34% | — | 2 ene 2026 | An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.… |
| CVE-2025-54165 | Media (4.6) | 0.34% | — | 2 ene 2026 | An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.… |
| CVE-2025-54164 | Media (4.6) | 0.34% | — | 2 ene 2026 | An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.… |
| CVE-2025-53596 | Baja (1.2) | 0.36% | — | 2 ene 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a… |
| CVE-2025-53593 | Baja (1.2) | 0.36% | — | 2 ene 2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash… |
| CVE-2025-53592 | Baja (1.3) | 0.34% | — | 2 ene 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a… |
| CVE-2025-53591 | Baja (1.2) | 0.34% | — | 2 ene 2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability… |
| CVE-2025-53590 | Baja (1.2) | 0.36% | — | 2 ene 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.