« Volver al listado

Qnap

Qnap Quts Hero: vulnerabilidades y CVE

Qnap Quts Hero tiene 234 vulnerabilidades publicadas, 73 de ellas en los últimos 12 meses. 11 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE234
Últimos 12 meses73
Críticas11
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2020-2509Crítica (9.8)34%⚠ Explotación activa17 abr 2021
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-24719Media (6.1)0.98%—10 jun 2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary…
CVE-2026-24717Baja (1.2)0.39%—10 jun 2026
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of…
CVE-2026-24716Baja (1.2)0.33%—10 jun 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a…
CVE-2026-22893Alta (8.6)1.1%—10 jun 2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary…
CVE-2025-66281Media (6.9)0.46%—10 jun 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-66280Media (5.1)0.44%—10 jun 2026
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to…
CVE-2025-66279Alta (8.6)1.1%—10 jun 2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary…
CVE-2025-66273Alta (8.6)1.1%—10 jun 2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary…
CVE-2025-62850Media (5.1)0.33%—10 jun 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a…
CVE-2025-62858Media (5.1)0.45%—9 jun 2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash…
CVE-2026-41539Media (6.3)0.33%—9 jun 2026
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application…
CVE-2024-14026Baja (2)0.62%—11 mar 2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the…
CVE-2025-66277Crítica (9.2)0.67%—11 feb 2026
A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have…
CVE-2025-66274Media (5.1)0.39%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a…
CVE-2025-59386Baja (1.2)0.39%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a…
CVE-2025-58466Baja (1.2)0.53%—11 feb 2026
A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to denial of…
CVE-2025-48725Baja (0.6)0.42%—11 feb 2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.…
CVE-2025-47205Media (5.1)0.44%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a…
CVE-2025-9110Baja (2.7)0.45%—2 ene 2026
An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to…
CVE-2025-59381Media (6.9)0.47%—2 ene 2026
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of…
CVE-2025-59380Media (4.6)0.58%—2 ene 2026
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of…
CVE-2025-62852Baja (1.2)0.36%—2 ene 2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash…
CVE-2025-48721Baja (1.2)0.43%—2 ene 2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash…
CVE-2025-57705Media (4.6)0.36%—2 ene 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the…
CVE-2025-54166Media (4.6)0.34%—2 ene 2026
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.…
CVE-2025-54165Media (4.6)0.34%—2 ene 2026
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.…
CVE-2025-54164Media (4.6)0.34%—2 ene 2026
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.…
CVE-2025-53596Baja (1.2)0.36%—2 ene 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a…
CVE-2025-53593Baja (1.2)0.36%—2 ene 2026
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash…
CVE-2025-53592Baja (1.3)0.34%—2 ene 2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter6
  2. T1210 Exploitation of Remote Services6
  3. T1190 Exploit Public-Facing Application4
  4. T1005 Data from Local System1
  5. T1078 Valid Accounts1
  6. T1499 Endpoint Denial of Service1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qnap