Skip to content
COOEY

FAIL › dossier

QNAP

VENDOR

· dossier confidence 60%

QNAP is a Taiwanese enterprise storage vendor whose products have been repeatedly compromised by critical remote code execution and command injection vulnerabilities. These flaws, often stemming from an insecure plugin architecture and improper access controls, have been actively exploited in ransomware campaigns, resulting in significant data breaches and system compromises.

PROFILE
CategoryEnterprise StorageWhat they doQNAP provides network-attached storage (NAS) devices, operating systems, and enterprise storage solutions for business and consumer markets.Founded2004HQTaiwan Websitehttps://www.qnap.com ↗
SECURITY POSTURE

QNAP has a poor security track record characterized by repeated critical remote code execution (RCE) and command injection vulnerabilities across its QTS operating system and NAS products, frequently exploited in ransomware campaigns. The company's plugin architecture and improper access controls have consistently allowed unauthenticated attackers to execute arbitrary commands and bypass authentication.

Notable failures
  • CVE-2022-27593 RCE in Photo Station exploited by Deadbolt ransomware
  • CVE-2019-7193 RCE in QTS exploited in ransomware attacks
  • CVE-2018-19949 command injection in File Station enabling ransomware
  • CVE-2023-47565 OS command injection in VioStar NVR
  • CVE-2020-2509 command injection in NAS devices
Patterns: repeated unpatched RCE and command injection vulnerabilities; insecure plugin architecture allowing unauthenticated command execution; improper access control and authentication bypass flaws
FAILURE HISTORY · 17
DATEEVENTSEVSUMMARY
2022-09-08 CVE-2022-27593 critical QNAP Photo Station's externally controlled reference vulnerability allowed attackers to modify system files and was actively exploited in a Deadbolt ransomware campaign.
2022-06-08 CVE-2019-7193 critical QNAP QTS suffered an improper input validation flaw allowing remote code execution, which was actively exploited in the wild and linked to ransomware attacks.
2022-05-24 CVE-2018-19949 critical QNAP NAS File Station suffered a critical command injection flaw that allowed remote attackers to execute arbitrary commands, directly enabling ransomware attacks.
2022-04-11 CVE-2020-2509 high QNAP NAS devices suffered a command injection vulnerability enabling remote code execution, actively exploited in ransomware campaigns.
2022-06-08 CVE-2019-7192 critical QNAP Photo Station's improper access control flaw allowed remote attackers to bypass authentication and gain unauthorized system access.
2022-06-08 CVE-2019-7194 critical QNAP Photo Station's path traversal flaw let attackers read/modify system files, serving as a ransomware entry point.
2022-06-08 CVE-2019-7195 critical QNAP Photo Station's path traversal flaw let attackers read/modify system files, serving as a ransomware entry point.
2022-05-24 CVE-2018-19953 critical QNAP NAS File Station XSS vulnerability allowed remote attackers to inject malicious code, linked to ransomware attacks.
2022-05-24 CVE-2018-19943 critical QNAP NAS devices were vulnerable to cross-site scripting, exploited in the wild, and linked to ransomware activity.
2022-03-31 CVE-2021-28799 critical QNAP NAS devices with HBS 3 allowed unauthorized remote logins due to an improper authorization vulnerability, actively exploited in ransomware attacks.
2023-12-21 CVE-2023-47565 high QNAP VioStor NVR allows authenticated attackers to execute OS commands via network, enabling remote code execution.
2022-03-25 CVE-2020-2506 high QNAP Helpdesk suffered an improper access control flaw allowing privilege escalation or data exposure.
2026-06-10 CVE-2026-26241 critical CVE-2026-26241: A buffer overflow vulnerability has been reported to affect File Station 5. The
2026-06-10 CVE-2026-26240 critical CVE-2026-26240: A buffer overflow vulnerability has been reported to affect File Station 5. The
2026-06-10 CVE-2025-66276 critical CVE-2025-66276: QuTS hero is not affected. We have already fixed the vulnerability in the follo
2026-06-09 CVE-2026-44083 critical CVE-2026-44083: An authorization bypass through user-controlled key vulnerability has been repor
2020-10-28 CVE-2018-19949 critical CVE-2018-19949: If exploited, this command injection vulnerability could allow remote attackers
SENTIMENT · TRUSTED SOURCES
synthesismixed-0.20
QNAP fixed the vulnerability, but the sources lack specific commentary on the vendor's response to CVE-2018-19949, focusing instead on general vulnerability data or unrelated events.
cooey ↗mixed+0.00
Neutral; provides factual details about the vulnerability and QNAP's patch without commentary.
"QNAP has already fixed the issue in the following QTS versions."
Neutral; provides general CVE database information without specific commentary on QNAP.
Neutral; discusses QNAP patching zero-days in 2025, unrelated to CVE-2018-19949.
"QNAP released urgent patches for seven zero-day flaws exposed during Pwn2Own 2025"
Neutral; provides a data breach directory without specific commentary on QNAP.
cvefeed.io ↗mixed+0.00
Neutral; provides CISA KEV catalog information without specific commentary on QNAP.
CISA ↗mixed+0.00
Neutral; provides CISA ICS advisories page without specific commentary on QNAP.
Neutral; provides FortiGuard PSIRT page without specific commentary on QNAP.
Open questions: Current patch cycle SLA for QNAP vulnerabilities · Specific remediation steps taken for CVE-2022-27593
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-18 04:26:13.683608+00:00