Vulnerabilities (CVE)

Filtered by vendor Qnap Subscribe
Total 461 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29884 1 Qnap 1 File Station 2025-06-18 N/A 8.8 HIGH
An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later and later
CVE-2025-29883 1 Qnap 1 File Station 2025-06-18 N/A 8.8 HIGH
An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later and later
CVE-2025-22490 1 Qnap 1 File Station 2025-06-18 N/A 7.5 HIGH
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later
CVE-2025-22486 1 Qnap 1 File Station 2025-06-18 N/A 8.8 HIGH
An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later and later
CVE-2017-17033 1 Qnap 1 Qts 2025-04-20 7.5 HIGH 9.8 CRITICAL
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
CVE-2017-13071 1 Qnap 2 Qts, Video Station 2025-04-20 7.5 HIGH 9.8 CRITICAL
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.
CVE-2017-13067 1 Qnap 1 Qts 2025-04-20 7.5 HIGH 9.8 CRITICAL
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerability allows a remote attacker to execute commands on a QNAP NAS using a transcoding service on port 9251. A remote user does not require any privileges to successfully execute an attack.
CVE-2017-17029 1 Qnap 1 Qts 2025-04-20 7.5 HIGH 9.8 CRITICAL
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
CVE-2017-17030 1 Qnap 1 Qts 2025-04-20 7.5 HIGH 9.8 CRITICAL
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
CVE-2017-13070 1 Qnap 1 Qsync 2025-04-20 9.3 HIGH 7.8 HIGH
A DLL Hijacking vulnerability in QNAP Qsync for Windows (exe) version 4.2.2.0724 and earlier could allow remote attackers to execute arbitrary code on Windows machines.
CVE-2017-6359 1 Qnap 1 Qts 2025-04-20 10.0 HIGH 9.8 CRITICAL
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
CVE-2017-17028 1 Qnap 1 Qts 2025-04-20 7.5 HIGH 9.8 CRITICAL
A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
CVE-2017-10700 1 Qnap 1 Qts 2025-04-20 10.0 HIGH 9.8 CRITICAL
In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.
CVE-2017-7629 1 Qnap 1 Qts 2025-04-20 5.0 MEDIUM 7.5 HIGH
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
CVE-2017-17027 1 Qnap 1 Qts 2025-04-20 7.5 HIGH 9.8 CRITICAL
A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
CVE-2017-13069 1 Qnap 1 Music Station 2025-04-20 7.5 HIGH 9.8 CRITICAL
QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a remote attacker to run arbitrary commands on the NAS.
CVE-2017-6360 1 Qnap 1 Qts 2025-04-20 10.0 HIGH 9.8 CRITICAL
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
CVE-2017-7876 1 Qnap 1 Qts 2025-04-20 7.5 HIGH 10.0 CRITICAL
This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and later versions.
CVE-2017-5227 1 Qnap 1 Qts 2025-04-20 5.0 MEDIUM 7.5 HIGH
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file.
CVE-2017-6361 1 Qnap 1 Qts 2025-04-20 10.0 HIGH 9.8 CRITICAL
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.