FAIL › dossier
QNAP
VENDOR· dossier confidence 60%
QNAP is a Taiwanese enterprise storage vendor whose products have been repeatedly compromised by critical remote code execution and command injection vulnerabilities. These flaws, often stemming from an insecure plugin architecture and improper access controls, have been actively exploited in ransomware campaigns, resulting in significant data breaches and system compromises.
QNAP has a poor security track record characterized by repeated critical remote code execution (RCE) and command injection vulnerabilities across its QTS operating system and NAS products, frequently exploited in ransomware campaigns. The company's plugin architecture and improper access controls have consistently allowed unauthenticated attackers to execute arbitrary commands and bypass authentication.
- CVE-2022-27593 RCE in Photo Station exploited by Deadbolt ransomware
- CVE-2019-7193 RCE in QTS exploited in ransomware attacks
- CVE-2018-19949 command injection in File Station enabling ransomware
- CVE-2023-47565 OS command injection in VioStar NVR
- CVE-2020-2509 command injection in NAS devices
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-09-08 | CVE-2022-27593 | critical | QNAP Photo Station's externally controlled reference vulnerability allowed attackers to modify system files and was actively exploited in a Deadbolt ransomware campaign. |
| 2022-06-08 | CVE-2019-7193 | critical | QNAP QTS suffered an improper input validation flaw allowing remote code execution, which was actively exploited in the wild and linked to ransomware attacks. |
| 2022-05-24 | CVE-2018-19949 | critical | QNAP NAS File Station suffered a critical command injection flaw that allowed remote attackers to execute arbitrary commands, directly enabling ransomware attacks. |
| 2022-04-11 | CVE-2020-2509 | high | QNAP NAS devices suffered a command injection vulnerability enabling remote code execution, actively exploited in ransomware campaigns. |
| 2022-06-08 | CVE-2019-7192 | critical | QNAP Photo Station's improper access control flaw allowed remote attackers to bypass authentication and gain unauthorized system access. |
| 2022-06-08 | CVE-2019-7194 | critical | QNAP Photo Station's path traversal flaw let attackers read/modify system files, serving as a ransomware entry point. |
| 2022-06-08 | CVE-2019-7195 | critical | QNAP Photo Station's path traversal flaw let attackers read/modify system files, serving as a ransomware entry point. |
| 2022-05-24 | CVE-2018-19953 | critical | QNAP NAS File Station XSS vulnerability allowed remote attackers to inject malicious code, linked to ransomware attacks. |
| 2022-05-24 | CVE-2018-19943 | critical | QNAP NAS devices were vulnerable to cross-site scripting, exploited in the wild, and linked to ransomware activity. |
| 2022-03-31 | CVE-2021-28799 | critical | QNAP NAS devices with HBS 3 allowed unauthorized remote logins due to an improper authorization vulnerability, actively exploited in ransomware attacks. |
| 2023-12-21 | CVE-2023-47565 | high | QNAP VioStor NVR allows authenticated attackers to execute OS commands via network, enabling remote code execution. |
| 2022-03-25 | CVE-2020-2506 | high | QNAP Helpdesk suffered an improper access control flaw allowing privilege escalation or data exposure. |
| 2026-06-10 | CVE-2026-26241 | critical | CVE-2026-26241: A buffer overflow vulnerability has been reported to affect File Station 5. The |
| 2026-06-10 | CVE-2026-26240 | critical | CVE-2026-26240: A buffer overflow vulnerability has been reported to affect File Station 5. The |
| 2026-06-10 | CVE-2025-66276 | critical | CVE-2025-66276: QuTS hero is not affected. We have already fixed the vulnerability in the follo |
| 2026-06-09 | CVE-2026-44083 | critical | CVE-2026-44083: An authorization bypass through user-controlled key vulnerability has been repor |
| 2020-10-28 | CVE-2018-19949 | critical | CVE-2018-19949: If exploited, this command injection vulnerability could allow remote attackers |
"QNAP has already fixed the issue in the following QTS versions."
"QNAP released urgent patches for seven zero-day flaws exposed during Pwn2Own 2025"
- QNAP Officially Launches AI Genius for Fast Information Access and ... · www.qnap.com
- HP Inc. (HPQ) Company Profile & Description - Stock Analysis · stockanalysis.com
- 威聯通 (7805.TWO) 基本資料 - Yahoo股市 · tw.stock.yahoo.com
- QNAP Bolsters NAS Security with Enhanced Ransomware Protection in ... · dailysecurityreview.com
- QNAP QTS: why vulnerabilities keep reappearing A study conducted by the ... · x.com
- 2026 重大漏洞整理:Synology、QNAP、Fortinet 必修清單 · www.yutuo-tech.com
- QNAP Turbo NAS System (QTS): Releases, patches & end-of-life · www.versio.io
- QNAP QTS: why vulnerabilities keep reappearing A study conducted by the ... · x.com
- QNAP NAS: Releases, Patches und End-of-Life - versio.io · www.versio.io