qnap security advisories
18 threat alerts tracking vulnerabilities and security advisories that affect qnap products.
Vulnios monitors qnap CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent qnap security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2017-17027 — qnap — qts
A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execu
criticalCVE-2017-17027Critical Vulnerability: CVE-2017-17033 — qnap — qts
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to
criticalCVE-2017-17033Critical Vulnerability: CVE-2017-17032 — qnap — qts
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to
criticalCVE-2017-17032Critical Vulnerability: CVE-2017-17030 — qnap — qts
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to ex
criticalCVE-2017-17030Critical Vulnerability: CVE-2017-17028 — qnap — qts
A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attac
criticalCVE-2017-17028Critical Vulnerability: CVE-2017-17031 — qnap — qts
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to
criticalCVE-2017-17031Critical Vulnerability: CVE-2017-17029 — qnap — qts
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to ex
criticalCVE-2017-17029Critical Vulnerability: CVE-2017-13071 — qnap — video_station, qts
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlie
criticalCVE-2017-13071Critical Vulnerability: CVE-2017-13069 — qnap — music_station
QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a
criticalCVE-2017-13069Critical Vulnerability: CVE-2017-10700 — qnap — qts
In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.
criticalCVE-2017-10700Critical Vulnerability: CVE-2017-13067 — qnap — qts
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerabilit
criticalCVE-2017-13067Critical Vulnerability: CVE-2017-12582 — qnap — ts-212p_firmware, ts-212p
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that un
criticalCVE-2017-12582Critical Vulnerability: CVE-2017-7876 — qnap — qts
This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 bui
criticalCVE-2017-7876Critical Vulnerability: CVE-2017-6359 — qnap — qts
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
criticalCVE-2017-6359Critical Vulnerability: CVE-2017-6360 — qnap — qts
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
criticalCVE-2017-6360Critical Vulnerability: CVE-2017-6361 — qnap — qts
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
criticalCVE-2017-6361Critical Vulnerability: CVE-2026-22898 — qnap — qvr_pro
A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already
criticalCVE-2026-22898Critical Vulnerability: CVE-2025-59383 — qnap — media_streaming_add-on
A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed
criticalCVE-2025-59383
Track qnap exposure across your environment
Vulnios automatically cross-references your asset inventory against new qnap CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan