CVE-2017-17029: QNAP QTS
Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
Affected products
- QNAP QTS: up to and including 4.3.3.0378; version 4.3.4.0358 only; version 4.3.4.0370 only; version 4.3.4.0372 only; version 4.3.4.0374 only; version 4.3.4.0387 only
Published 2017-12-21. Last modified 2026-06-17.