Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

QSAN — Vulnerabilities & Security Advisories 31

Browse all 31 CVE security advisories affecting QSAN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QSAN operates primarily in the network-attached storage and data management sector, providing hardware and software solutions for enterprise data protection and virtualization. Security audits reveal a concerning history of thirty-one recorded Common Vulnerabilities and Exposures, indicating persistent weaknesses in their product lifecycle management. The most prevalent vulnerability classes include remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from insufficient input validation and improper access controls within their web-based management interfaces. These defects allow attackers to potentially gain unauthorized administrative access or execute arbitrary commands on affected storage systems. While no single catastrophic public breach has been widely documented as a direct result of these specific CVEs, the high volume of disclosed issues suggests systemic gaps in secure coding practices. Organizations utilizing QSAN infrastructure must prioritize rigorous patching and network segmentation to mitigate the risk of exploitation inherent in these known defects.

Found 23 results / 31Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2021-32528 QSAN Storage Manager - Exposure of Sensitive Information to an Unauthorized Actor — Storage ManagerCWE-200 5.3 Medium2021-07-07
CVE-2021-32527 QSAN Storage Manager - Path Traversal-2 — Storage ManagerCWE-22 7.5 High2021-07-07
CVE-2021-32526 QSAN Storage Manager - Incorrect Permission Assignment for Critical Resource — Storage ManagerCWE-732 6.5 Medium2021-07-07
CVE-2021-32525 QSAN Storage Manager - Use of Hard-coded Password-2 — Storage ManagerCWE-259 9.1 Critical2021-07-07
CVE-2021-32524 QSAN Storage Manager - Command Injection-3 — Storage ManagerCWE-78 9.1 Critical2021-07-07
CVE-2021-32523 QSAN Storage Manager - Improper Authorization — Storage ManagerCWE-285 9.1 Critical2021-07-07
CVE-2021-32522 QSAN Storage Manager, XEVO, SANOS - Improper Restriction of Excessive Authentication Attempts — Storage ManagerCWE-307 9.8 Critical2021-07-07
CVE-2021-32521 QSAN Storage Manager, XEVO, SANOS - Use of Hard-coded Password — Storage ManagerCWE-259 7.3 High2021-07-07
CVE-2021-32520 QSAN Storage Manager - Use of Hard-coded Cryptographic Key — Storage ManagerCWE-321 9.8 Critical2021-07-07
CVE-2021-32519 QSAN Storage Manager, XEVO, SANOS - Use of Password Hash With Insufficient Computational Effort — Storage ManagerCWE-916 9.8 Critical2021-07-07
CVE-2021-32518 QSAN Storage Manager - UNIX Symbolic Link (Symlink) Following — Storage ManagerCWE-61 7.5 High2021-07-07
CVE-2021-32517 QSAN Storage Manager - Improper Access Control — Storage ManagerCWE-284 7.5 High2021-07-07
CVE-2021-32516 QSAN Storage Manager - Path Traversal — Storage ManagerCWE-22 7.5 High2021-07-07
CVE-2021-32515 QSAN Storage Manager - Exposure of Information Through Directory Listing — Storage ManagerCWE-548 5.3 Medium2021-07-07
CVE-2021-32514 QSAN Storage Manager - Improper Access Control Following via FirwareUpgrade function — Storage ManagerCWE-284 7.5 High2021-07-07
CVE-2021-32513 QSAN Storage Manager - Command Injection Following via QsanTorture function — Storage ManagerCWE-78 9.8 Critical2021-07-07
CVE-2021-32512 QSAN Storage Manager - Command Injection Following via QuickInstall function — Storage ManagerCWE-78 9.8 Critical2021-07-07
CVE-2021-32511 QSAN Storage Manager - Exposure of Information Through Directory Listing Following via ViewBroserList function — Storage ManagerCWE-548 4.3 Medium2021-07-07
CVE-2021-32510 QSAN Storage Manager - Exposure of Information Through Directory Listing Following via Antivirus function — Storage ManagerCWE-548 4.3 Medium2021-07-07
CVE-2021-32509 QSAN Storage Manager - UNIX Symbolic Link (Symlink) Following via FileviewDoc function — Storage ManagerCWE-61 6.5 Medium2021-07-07
CVE-2021-32508 QSAN Storage Manager - UNIX Symbolic Link (Symlink) Following via FileStreaming function — Storage ManagerCWE-61 6.5 Medium2021-07-07
CVE-2021-32507 QSAN Storage Manager - Absolute Path Traversal via FileDownload function — Storage ManagerCWE-36 6.5 Medium2021-07-07
CVE-2021-32506 QSAN Storage Manager - Absolute Path Traversal via GetImage function — Storage ManagerCWE-36 6.5 Medium2021-07-07

This page lists every published CVE security advisory associated with QSAN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.