📦 Quts Hero

by Qnap

🔍 What is Quts Hero?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-66277

CRITICAL CVSS 9.8 Feb 11, 2026

This CVE describes a link following vulnerability in QNAP operating systems that allows remote attackers to traverse the file system to unintended locations. The vulnerability affects multiple QNAP OS...

CVE-2025-59385

CRITICAL CVSS 9.8 Dec 16, 2025

This CVE describes an authentication bypass vulnerability in QNAP operating systems that allows remote attackers to spoof authentication and access restricted resources without valid credentials. It a...

CVE-2025-62849

CRITICAL CVSS 9.8 Dec 16, 2025

This SQL injection vulnerability in QNAP operating systems allows remote attackers to execute arbitrary SQL commands. If exploited, attackers could execute unauthorized code or commands on affected QN...

CVE-2024-21899

CRITICAL CVSS 9.8 Mar 8, 2024

This CVE-2024-21899 is an improper authentication vulnerability in QNAP operating systems that allows attackers to bypass authentication mechanisms and potentially gain unauthorized access to the syst...

CVE-2023-45025

CRITICAL CVSS 9.0 Feb 2, 2024

This CVE describes an OS command injection vulnerability in multiple QNAP operating system versions that allows authenticated users to execute arbitrary commands via network requests. Attackers could ...

CVE-2021-28802

CRITICAL CVSS 9.8 Jul 1, 2021

This CVE-2021-28802 is a critical command injection vulnerability in QNAP QTS and QuTS hero operating systems that allows attackers to execute arbitrary commands on affected devices. Attackers could p...

CVE-2021-28804

CRITICAL CVSS 9.8 Jul 1, 2021

This CVE-2021-28804 is a critical command injection vulnerability in QNAP QTS and QuTS hero operating systems that allows attackers to execute arbitrary commands on affected devices. Attackers can pot...

CVE-2020-2509

CRITICAL CVSS 9.8 Apr 17, 2021

This is a critical command injection vulnerability (CWE-77) in QNAP QTS and QuTS hero operating systems that allows attackers to execute arbitrary commands on affected devices. If exploited, attackers...

CVE-2019-7198

CRITICAL CVSS 9.8 Dec 10, 2020

CVE-2019-7198 is a command injection vulnerability in QNAP NAS devices that allows attackers to execute arbitrary commands on affected systems. This affects QNAP QTS and QuTS hero operating systems be...

CVE-2025-48725

HIGH CVSS 8.1 Feb 11, 2026

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects users running vulnerable QNAP OS versions. Attackers n...

CVE-2025-9110

HIGH CVSS 7.5 Jan 2, 2026

This CVE-2025-9110 vulnerability allows remote attackers to read sensitive system information from affected QNAP devices without authorization. Attackers can exploit this to access application data th...

CVE-2025-52863

HIGH CVSS 8.1 Jan 2, 2026

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects QNAP NAS devices running vulnerable QTS and QuTS hero ...

CVE-2025-52864

HIGH CVSS 8.1 Jan 2, 2026

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects users running vulnerable QTS and QuTS hero versions. A...

CVE-2025-52872

HIGH CVSS 8.1 Jan 2, 2026

A buffer overflow vulnerability in QNAP operating systems allows authenticated remote attackers to modify memory or crash processes. This affects users running vulnerable QTS and QuTS hero versions. A...

CVE-2025-62847

HIGH CVSS 7.5 Dec 16, 2025

This CVE describes an argument injection vulnerability in QNAP operating systems where attackers can manipulate command arguments to alter execution logic. It affects multiple QNAP NAS devices running...

CVE-2025-47212

HIGH CVSS 7.2 Oct 3, 2025

A command injection vulnerability in QNAP operating systems allows authenticated attackers with administrator privileges to execute arbitrary commands on affected devices. This affects QNAP NAS device...

CVE-2025-30273

HIGH CVSS 8.1 Aug 29, 2025

An out-of-bounds write vulnerability in QNAP operating systems allows authenticated remote attackers to modify or corrupt memory. This affects QNAP NAS devices running vulnerable QTS and QuTS hero ver...

CVE-2025-30264

HIGH CVSS 8.8 Aug 29, 2025

This CVE describes a command injection vulnerability in QNAP operating systems that allows authenticated attackers to execute arbitrary commands on affected devices. The vulnerability affects multiple...

CVE-2025-22481

HIGH CVSS 8.8 Jun 6, 2025

A command injection vulnerability in QNAP operating systems allows authenticated remote attackers to execute arbitrary commands on affected devices. This affects QTS and QuTS hero users running vulner...

CVE-2024-53697

HIGH CVSS 7.2 Mar 7, 2025

This CVE describes an out-of-bounds write vulnerability in QNAP operating systems that could allow remote attackers with administrator access to modify or corrupt memory. The vulnerability affects mul...

CVE-2024-53699

HIGH CVSS 7.2 Mar 7, 2025

An out-of-bounds write vulnerability in QNAP operating systems could allow remote attackers with administrator access to modify or corrupt memory. This affects QTS and QuTS hero users running vulnerab...

CVE-2024-53693

HIGH CVSS 7.1 Mar 7, 2025

This CRLF injection vulnerability in QNAP operating systems allows attackers with user access to manipulate application data by injecting carriage return and line feed sequences. It affects QTS and Qu...

CVE-2024-38638

HIGH CVSS 7.2 Mar 7, 2025

An out-of-bounds write vulnerability in QNAP operating systems allows remote attackers with administrator access to modify or corrupt memory. This affects QTS and QuTS hero versions before the patched...

CVE-2024-50402

HIGH CVSS 7.2 Dec 6, 2024

This CVE describes a format string vulnerability in QNAP operating systems that allows attackers with administrator access to read sensitive data or modify memory. The vulnerability affects multiple Q...

CVE-2024-48867

HIGH CVSS 7.5 Dec 6, 2024

This CRLF injection vulnerability in QNAP operating systems allows remote attackers to inject carriage return and line feed sequences, potentially modifying application data. It affects multiple QTS a...

CVE-2024-50400

HIGH CVSS 7.2 Nov 22, 2024

A format string vulnerability in QNAP operating systems allows remote attackers with administrator access to read sensitive data or modify memory. This affects QTS and QuTS hero systems running vulner...

CVE-2024-50396

HIGH CVSS 8.8 Nov 22, 2024

A format string vulnerability in QNAP operating systems allows remote attackers to read sensitive memory or modify memory contents. This affects QTS and QuTS hero users running vulnerable versions. Su...

CVE-2024-50398

HIGH CVSS 7.2 Nov 22, 2024

This CVE describes a format string vulnerability in QNAP operating systems that allows attackers with administrator access to read sensitive data or modify memory. The vulnerability affects multiple Q...

CVE-2024-37041

HIGH CVSS 7.2 Nov 22, 2024

This CVE describes a buffer overflow vulnerability in QNAP operating systems that allows remote attackers with administrator access to execute arbitrary code. The vulnerability affects multiple QNAP N...

CVE-2024-37044

HIGH CVSS 7.2 Nov 22, 2024

This CVE describes a buffer overflow vulnerability in QNAP operating systems that allows remote attackers with administrator access to execute arbitrary code. The vulnerability affects multiple QNAP N...

CVE-2023-51366

HIGH CVSS 8.7 Sep 6, 2024

This path traversal vulnerability in QNAP operating systems allows authenticated users to access files outside intended directories via network requests. It affects multiple QNAP NAS devices running v...

CVE-2024-21897

HIGH CVSS 8.9 Sep 6, 2024

This cross-site scripting (XSS) vulnerability in QNAP operating systems allows authenticated attackers to inject malicious scripts into web applications. The vulnerability affects multiple QNAP NAS de...

CVE-2023-34974

HIGH CVSS 8.8 Sep 6, 2024

This CVE describes an OS command injection vulnerability in QNAP operating systems that allows authenticated users to execute arbitrary commands via network requests. It affects QTS and QuTS hero syst...

CVE-2023-39298

HIGH CVSS 7.8 Sep 6, 2024

This CVE describes a missing authorization vulnerability in QNAP operating systems that allows local authenticated users to access data or perform actions beyond their intended permissions. The vulner...

CVE-2024-27130

HIGH CVSS 7.2 May 21, 2024

This CVE describes a buffer overflow vulnerability in QNAP operating systems that allows attackers to execute arbitrary code remotely. It affects multiple QNAP NAS devices running vulnerable QTS and Q...

CVE-2024-27127

HIGH CVSS 7.2 May 21, 2024

This double free vulnerability in QNAP operating systems allows authenticated attackers to execute arbitrary code remotely. It affects multiple QNAP NAS devices running vulnerable QTS and QuTS hero ve...

CVE-2024-27124

HIGH CVSS 7.5 Apr 26, 2024

This CVE describes an OS command injection vulnerability in multiple QNAP operating system versions that allows authenticated users to execute arbitrary commands via network requests. Attackers could ...

CVE-2023-50363

HIGH CVSS 7.4 Apr 26, 2024

This CVE describes an incorrect authorization vulnerability in QNAP operating systems that allows authenticated users to bypass intended access restrictions. Attackers with valid credentials could acc...

CVE-2023-51364

HIGH CVSS 8.7 Apr 26, 2024

This CVE-2023-51364 is a path traversal vulnerability in multiple QNAP operating system versions that allows authenticated users to read arbitrary files via network requests. It affects QTS, QuTS hero...

CVE-2023-47568

HIGH CVSS 8.8 Feb 2, 2024

This SQL injection vulnerability in QNAP operating systems allows authenticated users to execute arbitrary SQL commands via network requests. It affects multiple QNAP OS versions and could lead to dat...

CVE-2023-39297

HIGH CVSS 8.8 Feb 2, 2024

This CVE describes an OS command injection vulnerability in multiple QNAP operating system versions that allows authenticated users to execute arbitrary commands via network requests. The vulnerabilit...

CVE-2023-39296

HIGH CVSS 7.5 Jan 5, 2024

A prototype pollution vulnerability in QNAP operating systems allows attackers to modify object prototypes, potentially causing system crashes via network requests. This affects QNAP NAS devices runni...

CVE-2023-32974

HIGH CVSS 7.5 Oct 13, 2023

This path traversal vulnerability in QNAP operating systems allows authenticated users to read arbitrary files outside intended directories via network requests. It affects multiple QNAP OS versions a...

CVE-2021-28798

HIGH CVSS 8.8 May 21, 2021

This CVE describes a relative path traversal vulnerability in QNAP NAS devices running QTS and QuTS hero operating systems. If exploited, attackers can modify system files, potentially compromising sy...

CVE-2025-59386

MEDIUM CVSS 4.9 Feb 11, 2026

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects multiple QNAP NAS devices ...

CVE-2025-58466

MEDIUM CVSS 4.9 Feb 11, 2026

A use of uninitialized variable vulnerability in QNAP operating systems allows attackers with administrator access to cause denial of service or manipulate program execution flow. This affects QTS and...

CVE-2025-59381

MEDIUM CVSS 4.9 Jan 2, 2026

A path traversal vulnerability in QNAP operating systems allows authenticated administrators to read arbitrary files. This affects QNAP NAS devices running vulnerable QTS and QuTS hero versions. Attac...

CVE-2025-62852

MEDIUM CVSS 6.5 Jan 2, 2026

A buffer overflow vulnerability in QNAP operating systems allows remote attackers with administrator credentials to modify memory or crash processes. This affects multiple QNAP NAS devices running vul...

CVE-2025-48721

MEDIUM CVSS 6.5 Jan 2, 2026

A buffer overflow vulnerability in QNAP operating systems allows remote attackers with administrator credentials to modify memory or crash processes. This affects QNAP NAS devices running vulnerable Q...

CVE-2025-59380

MEDIUM CVSS 4.9 Jan 2, 2026

This CVE describes a path traversal vulnerability in QNAP operating systems that allows authenticated attackers with administrator privileges to read arbitrary files. The vulnerability affects multipl...

CVE-2025-54166

MEDIUM CVSS 4.9 Jan 2, 2026

An out-of-bounds read vulnerability in QNAP operating systems allows remote attackers with administrator credentials to read sensitive memory data. This affects QTS and QuTS hero systems running vulne...

CVE-2025-57705

MEDIUM CVSS 4.9 Jan 2, 2026

This CVE describes a resource allocation vulnerability in QNAP operating systems where an authenticated attacker with administrator privileges can exhaust system resources, causing denial of service f...

CVE-2025-53593

MEDIUM CVSS 6.5 Jan 2, 2026

A buffer overflow vulnerability in QNAP operating systems allows remote attackers with administrator credentials to modify memory or crash processes. This affects multiple QNAP NAS devices running vul...

CVE-2025-53596

MEDIUM CVSS 4.9 Jan 2, 2026

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects multiple QNAP NAS devices ...

CVE-2025-54164

MEDIUM CVSS 4.9 Jan 2, 2026

An out-of-bounds read vulnerability in QNAP operating systems allows remote attackers with administrator credentials to read sensitive memory data. This affects QNAP NAS devices running vulnerable QTS...

CVE-2025-54165

MEDIUM CVSS 4.9 Jan 2, 2026

An out-of-bounds read vulnerability in QNAP operating systems allows remote attackers with administrator credentials to read sensitive memory contents. This affects QNAP NAS devices running vulnerable...

CVE-2025-53405

MEDIUM CVSS 4.9 Jan 2, 2026

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects QNAP NAS devices running v...

CVE-2025-53589

MEDIUM CVSS 4.9 Jan 2, 2026

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects multiple QNAP NAS devices ...

CVE-2025-53590

MEDIUM CVSS 4.9 Jan 2, 2026

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects QNAP NAS devices running v...

CVE-2025-53591

MEDIUM CVSS 6.5 Jan 2, 2026

A format string vulnerability in QNAP operating systems allows attackers with administrator access to read sensitive data or modify memory. This affects multiple QNAP NAS devices running vulnerable QT...

CVE-2025-53414

MEDIUM CVSS 4.9 Jan 2, 2026

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects QNAP NAS devices running v...

CVE-2025-53592

MEDIUM CVSS 6.5 Jan 2, 2026

A NULL pointer dereference vulnerability in QNAP operating systems allows authenticated remote attackers to cause denial-of-service conditions. This affects QNAP NAS devices running vulnerable QTS and...

CVE-2025-47208

MEDIUM CVSS 6.5 Jan 2, 2026

This CVE describes a resource exhaustion vulnerability in QNAP operating systems where authenticated remote attackers can allocate resources without limits, potentially causing denial-of-service condi...

CVE-2025-52426

MEDIUM CVSS 4.9 Jan 2, 2026

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects QNAP NAS devices running v...

CVE-2025-52430

MEDIUM CVSS 4.9 Jan 2, 2026

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects multiple QNAP NAS devices ...

CVE-2025-52431

MEDIUM CVSS 4.9 Jan 2, 2026

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects QNAP NAS devices running v...

CVE-2025-44013

MEDIUM CVSS 6.5 Jan 2, 2026

A NULL pointer dereference vulnerability in QNAP operating systems allows authenticated remote attackers to cause denial-of-service conditions. This affects QNAP NAS devices running vulnerable QTS and...

CVE-2025-52862

MEDIUM CVSS 4.9 Oct 3, 2025

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects QTS and QuTS hero systems ...

CVE-2025-53407

MEDIUM CVSS 6.5 Oct 3, 2025

A format string vulnerability in QNAP operating systems allows attackers with administrator access to read sensitive data or modify memory. This affects QTS and QuTS hero systems running vulnerable ve...

CVE-2025-52854

MEDIUM CVSS 4.9 Oct 3, 2025

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects QTS and QuTS hero systems ...

CVE-2025-52857

MEDIUM CVSS 4.9 Oct 3, 2025

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects QNAP NAS devices running v...

CVE-2025-52859

MEDIUM CVSS 4.9 Oct 3, 2025

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects QTS and QuTS hero systems ...

CVE-2025-52432

MEDIUM CVSS 4.9 Oct 3, 2025

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects multiple QNAP NAS devices ...

CVE-2025-52853

MEDIUM CVSS 4.9 Oct 3, 2025

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service conditions. This affects QTS and QuTS hero systems ...