Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

QNAP Systems Inc. — Vulnerabilities & Security Advisories 532

Browse all 532 CVE security advisories affecting QNAP Systems Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QNAP Systems Inc. manufactures network-attached storage devices and enterprise storage solutions, primarily serving small to medium-sized businesses and home users seeking centralized data management. Historically, the company’s firmware has exhibited a high volume of vulnerabilities, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within the web management interface or embedded services. Notable incidents involve critical RCE vulnerabilities that allow unauthenticated attackers to gain full system control, exposing connected data to theft or ransomware encryption. The sheer number of recorded CVEs highlights persistent challenges in secure coding practices and rigorous patch management across its diverse product line. While QNAP provides security updates, the frequency of disclosed flaws necessitates strict network segmentation and proactive monitoring for administrators relying on these storage appliances for critical infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2020-2495 Cross-site scripting vulnerability in QTS and QuTS hero — QTSCWE-79 6.1 -2020-12-10
CVE-2020-2494 Cross-site Scripting Vulnerability in Music Station — Music StationCWE-79 6.1 -2020-12-10
CVE-2020-2493 Cross-site Scripting Vulnerability in Multimedia Console — Multimedia ConsoleCWE-79 6.1 -2020-12-10
CVE-2019-7198 Command Injection Vulnerability in QTS and QuTS hero — QTSCWE-77 9.8 -2020-12-10
CVE-2020-2491 Cross-site Scripting Vulnerability in Photo Station — Photo StationCWE-79 6.1 -2020-12-10
CVE-2020-2490 QNAP Systems QNAP QTS 命令注入漏洞 — QTSCWE-77 7.2 High2020-11-16
CVE-2020-2492 QNAP Systems QNAP QTS 命令注入漏洞 — QTSCWE-77 7.2 High2020-11-16
CVE-2018-19950 QNAP Systems TS-870 命令注入漏洞 — Music StationCWE-77 9.8 -2020-11-02
CVE-2018-19951 QNAP Systems TS-870 跨站脚本漏洞 — Music StationCWE-79 6.1 -2020-11-02
CVE-2018-19952 QNAP Systems TS-870 SQL注入漏洞 — Music StationCWE-20 7.5 -2020-11-02
CVE-2018-19954 QNAP Systems TS-870 跨站脚本漏洞 — Photo StationCWE-79 6.1 -2020-11-02
CVE-2018-19955 QNAP Systems TS-870 跨站脚本漏洞 — Photo StationCWE-79 6.1 -2020-11-02
CVE-2018-19956 QNAP Systems TS-870 跨站脚本漏洞 — Photo StationCWE-79 6.1 -2020-11-02
CVE-2018-19943 QNAP Systems TS-870 跨站脚本漏洞 — QTSCWE-79 8.0 High2020-10-28
CVE-2018-19949 QNAP Systems TS-870 命令注入漏洞 — QTSCWE-20 9.8 -2020-10-28
CVE-2018-19953 QNAP Systems TS-870 跨站脚本漏洞 — QTSCWE-79 6.1 -2020-10-28
CVE-2018-19946 QNAP Systems TS-870 安全漏洞 — HelpdeskCWE-295 4.2 Medium2020-09-11
CVE-2018-19947 QNAP Systems TS-870 安全漏洞 — HelpdeskCWE-200 4.3 Medium2020-09-11
CVE-2018-19948 QNAP Systems TS-870 跨站请求伪造漏洞 — HelpdeskCWE-352 2.0 Low2020-09-11
CVE-2020-2500 QNAP Systems Helpdesk 信任管理问题漏洞 — HelpdeskCWE-284 9.8 Critical2020-07-01
CVE-2018-0721 Security Advisory for Vulnerabilities in QTS — QTSCWE-120 7.7 High2018-11-27
CVE-2018-0719 Security Advisory for Vulnerabilities in QTS — QTSCWE-79 5.5 Medium2018-11-27

This page lists every published CVE security advisory associated with QNAP Systems Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.