An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. QuTScloud, QVR, QES are not affected. We have already fixed the vulnerability in the following versions: QTS 4.5.4.2790 build 20240605 and later QuTS hero h4.5.4.2626 build 20231225 and later
2024-09-06T17:15:11.440
2024-09-13T21:14:11.960
Analyzed
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | qnap | qts | 4.5.4.1715 | Yes |
Operating System | qnap | qts | 4.5.4.1723 | Yes |
Operating System | qnap | qts | 4.5.4.1741 | Yes |
Operating System | qnap | qts | 4.5.4.1787 | Yes |
Operating System | qnap | qts | 4.5.4.1800 | Yes |
Operating System | qnap | qts | 4.5.4.1892 | Yes |
Operating System | qnap | qts | 4.5.4.1931 | Yes |
Operating System | qnap | qts | 4.5.4.2012 | Yes |
Operating System | qnap | qts | 4.5.4.2117 | Yes |
Operating System | qnap | qts | 4.5.4.2280 | Yes |
Operating System | qnap | qts | 4.5.4.2374 | Yes |
Operating System | qnap | qts | 4.5.4.2467 | Yes |
Operating System | qnap | qts | 4.5.4.2627 | Yes |
Operating System | qnap | quts_hero | h4.5.4.1771 | Yes |
Operating System | qnap | quts_hero | h4.5.4.1800 | Yes |
Operating System | qnap | quts_hero | h4.5.4.1813 | Yes |
Operating System | qnap | quts_hero | h4.5.4.1848 | Yes |
Operating System | qnap | quts_hero | h4.5.4.1892 | Yes |
Operating System | qnap | quts_hero | h4.5.4.1951 | Yes |
Operating System | qnap | quts_hero | h4.5.4.1971 | Yes |
Operating System | qnap | quts_hero | h4.5.4.1991 | Yes |
Operating System | qnap | quts_hero | h4.5.4.2052 | Yes |
Operating System | qnap | quts_hero | h4.5.4.2138 | Yes |
Operating System | qnap | quts_hero | h4.5.4.2217 | Yes |
Operating System | qnap | quts_hero | h4.5.4.2272 | Yes |
Operating System | qnap | quts_hero | h4.5.4.2374 | Yes |
Operating System | qnap | quts_hero | h4.5.4.2476 | Yes |
Operating System | qnap | quts_hero | h4.5.4.2626 | Yes |