Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

QNAP — Vulnerabilities & Security Advisories 36

Browse all 36 CVE security advisories affecting QNAP. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QNAP Systems specializes in network-attached storage (NAS) solutions, providing data storage and management infrastructure for both consumer and enterprise environments. Historically, its firmware has been a frequent target for security researchers, resulting in numerous recorded vulnerabilities. Common flaw classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, often stemming from insufficient input validation in web management interfaces or exposed APIs. These weaknesses have allowed attackers to gain unauthorized administrative access, potentially leading to complete system compromise or data exfiltration. While the company issues regular security updates, the high volume of past issues highlights challenges in secure development practices. Recent incidents have underscored the critical importance of timely patching and network segmentation for devices running QNAP operating systems to mitigate the risk of exploitation by automated threat actors.

CVE IDTitleCVSSSeverityPublished
CVE-2018-0722 QNAP Systems QNAP QTS Photo Station 路径遍历漏洞 — Photo Station 7.5 -2019-02-01
CVE-2018-0724 QNAP Q'center Virtual Appliance 跨站脚本漏洞 — Q'center Virtual Appliance 6.1 -2018-12-26
CVE-2018-0723 QNAP Q'center Virtual Appliance 跨站脚本漏洞 — Q'center Virtual Appliance 6.1 -2018-12-26
CVE-2018-0716 QNAP QTS Qsync Central 跨站脚本漏洞 — Qsync Central 6.1 -2018-11-30
CVE-2018-14749 QNAP QTS 缓冲区错误漏洞 — QNAP QTS 9.8 -2018-11-28
CVE-2018-14748 QNAP QTS 安全漏洞 — QNAP QTS 7.5 -2018-11-28
CVE-2018-14747 QNAP QTS 安全漏洞 — QNAP QTS 7.5 -2018-11-28
CVE-2018-14746 QNAP QTS 命令注入漏洞 — QNAP QTS 9.8 -2018-11-28
CVE-2018-0718 QNAP QTS Music Station 命令注入漏洞 — Music Station 9.8 -2018-09-14
CVE-2018-0715 QNAP Photo Station 跨站脚本漏洞 — Photo Station 6.1 -2018-08-27
CVE-2018-0714 QNAP QTS Helpdesk 命令注入漏洞 — Helpdesk in QTS 9.8 -2018-08-13
CVE-2018-0706 QNAP Q'center Virtual Appliance 安全漏洞 — Q'center Virtual Appliance 6.5 -2018-07-16
CVE-2018-0710 QNAP Q'center Virtual Appliance 命令注入漏洞 — Q'center Virtual Appliance 8.8 -2018-07-16
CVE-2018-0709 QNAP Q'center Virtual Appliance 命令注入漏洞 — Q'center Virtual Appliance 8.8 -2018-07-16
CVE-2018-0708 QNAP Q'center Virtual Appliance 命令注入漏洞 — Q'center Virtual Appliance 8.8 -2018-07-16
CVE-2018-0707 QNAP Q'center Virtual Appliance 命令注入漏洞 — Q'center Virtual Appliance 8.8 -2018-07-16
CVE-2017-13072 QNAP QTS APP Center 跨站脚本漏洞 — App Center in QTS 6.1 -2018-06-21
CVE-2018-0712 QNAP QTS LDAP Server 命令注入漏洞 — LDAP Server in QTS 9.8 -2018-06-21
CVE-2018-0711 QNAP QTS 跨站脚本漏洞 — QTS 6.1 -2018-04-30
CVE-2017-13073 QNAP NAS application Photo Station 跨站脚本漏洞 — Photo Station 6.1 -2018-04-23
CVE-2017-7641 QNAP NAS application Media Streaming add-on 安全漏洞 — QNAP Media Streaming Add-On 8.8 -2018-03-08
CVE-2017-7638 QNAP NAS application Media Streaming add-on 安全漏洞 — QNAP Media Streaming Add-On 6.5 -2018-03-08
CVE-2017-7634 QNAP NAS application Media Streaming add-on 跨站脚本漏洞 — QNAP Media Streaming Add-On 6.1 -2018-03-08
CVE-2017-7640 QNAP NAS application Media Streaming add-on 安全漏洞 — QNAP Media Streaming Add-On 9.8 -2018-03-08
CVE-2017-7633 QNAP Qfinder Pro 安全漏洞 — Qfinder Pro 7.5 -2018-03-05
CVE-2017-17031 QNAP QTS 缓冲区错误漏洞 — QTS Password function 9.8 -2017-12-21
CVE-2017-17027 QNAP QTS 缓冲区错误漏洞 — QTS FTP service 9.8 -2017-12-21
CVE-2017-17028 QNAP QTS 缓冲区错误漏洞 — QTS External Device function 9.8 -2017-12-21
CVE-2017-17029 QNAP QTS 缓冲区错误漏洞 — QTS Login function 9.8 -2017-12-21
CVE-2017-17030 QNAP QTS 缓冲区错误漏洞 — QTS Login function 9.8 -2017-12-21

This page lists every published CVE security advisory associated with QNAP. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.