QNAP Vulnerabilities
QNAP is known for network-attached storage (NAS) devices, and KEV entries cover its NAS operating system and apps such as Photo Station. The database tracks 12 QNAP CVE records. CISA lists 12 of them as exploited in the wild, most recently on 2023-12-21. The most affected products are Network Attached Storage (NAS), Photo Station, Helpdesk.
Recently Exploited QNAP CVEs
Legacy VioStor NVR
DeadBolt Ransomware
QNAP Photo Station Path Traversal Vulnerability
QNAP Photo Station Improper Access Control Vulnerability
QNAP Photo Station Path Traversal Vulnerability
QNAP QTS Improper Input Validation Vulnerability
Affected Products
6 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Network Attached Storage (NAS) | 4 | 4 | 2022-05-24 |
| Photo Station | 4 | 4 | 2022-09-08 |
| Helpdesk | 1 | 1 | 2022-03-25 |
| QNAP Network-Attached Storage (NAS) | 1 | 1 | 2022-04-11 |
| QTS | 1 | 1 | 2022-06-08 |
| VioStor NVR | 1 | 1 | 2023-12-21 |
Security Advisories
All QNAP CVEs
12 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2023-47565 | Legacy VioStor NVR | QNAP Systems Inc. | 8.0 | 73.3% | KEV | 2023-12-08 |
| CVE-2022-27593 | DeadBolt Ransomware | QNAP Systems Inc. | 10.0 | 87.9% | KEV | 2022-09-08 |
| CVE-2019-7195 | QNAP Photo Station Path Traversal Vulnerability | - | 9.8 | 89.5% | KEV | 2019-12-05 |
| CVE-2019-7192 | QNAP Photo Station Improper Access Control Vulnerability | - | 9.8 | 88.1% | KEV | 2019-12-05 |
| CVE-2019-7194 | QNAP Photo Station Path Traversal Vulnerability | - | 9.8 | 83.1% | KEV | 2019-12-05 |
| CVE-2019-7193 | QNAP QTS Improper Input Validation Vulnerability | - | 9.8 | 14.4% | KEV | 2019-12-05 |
| CVE-2018-19953 | QNAP NAS File Station Cross-Site Scripting Vulnerability | QNAP Systems Inc. | 6.1 | 29.0% | KEV | 2020-10-28 |
| CVE-2018-19949 | QNAP NAS File Station Command Injection Vulnerability | QNAP Systems Inc. | 9.8 | 28.6% | KEV | 2020-10-28 |
| CVE-2018-19943 | QNAP NAS File Station Cross-Site Scripting Vulnerability | QNAP Systems Inc. | 8.0 | 21.5% | KEV | 2020-10-28 |
| CVE-2020-2509 | Command Injection Vulnerability in QTS and QuTS hero | QNAP Systems Inc. | 9.8 | 34.0% | KEV | 2021-04-17 |
| CVE-2021-28799 | Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync) | QNAP Systems Inc. | 10.0 | 78.3% | KEV | 2021-05-13 |
| CVE-2020-2506 | improper access control vulnerability in Helpdesk | QNAP Systems Inc. | 7.3 | 2.0% | KEV | 2021-02-03 |
Frequently Asked Questions
How many QNAP vulnerabilities are actively exploited?→
12 QNAP CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2023-12-21.
Which QNAP vulnerabilities are used in ransomware attacks?→
CISA marks 9 QNAP KEV entries as known to be used in ransomware campaigns, including CVE-2022-27593, CVE-2019-7195, CVE-2019-7192, CVE-2019-7194, CVE-2019-7193.
Which QNAP products have the most exploited vulnerabilities?→
- +Network Attached Storage (NAS): 4 CVEs (4 in KEV)
- +Photo Station: 4 CVEs (4 in KEV)
- +Helpdesk: 1 CVE (1 in KEV)
- +QNAP Network-Attached Storage (NAS): 1 CVE (1 in KEV)
- +QTS: 1 CVE (1 in KEV)
Where does QNAP publish security advisories?→
QNAP publishes security advisories at https://www.qnap.com/en/security-advisories. Check the vendor advisory for fixed versions and workarounds before applying updates.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by QNAP, MITRE, CISA, or FIRST.