CVE-2023-23367: QNAP QTS

High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QuTS hero h5.0.1.2376 build 20230421 and later QuTScloud c5.1.0.2498 and later

Affected products

  • QNAP QTS: version 5.0.0.1716 only; version 5.0.0.1785 only; version 5.0.0.1808 only; version 5.0.0.1828 only; version 5.0.0.1837 only; version 5.0.0.1850 only; …
  • QNAP Quts Hero: version h5.0.0.1772 only; version h5.0.0.1844 only; version h5.0.0.1856 only; version h5.0.0.1892 only; version h5.0.0.1900 only; version h5.0.0.1949 only; …
  • QNAP Qutscloud: version c5.0.0.1919 only; version c5.0.1.1949 only; version c5.0.1.1998 only; version c5.0.1.2044 only; version c5.0.1.2148 only; version c5.0.1.2374 only

Published 2023-11-10. Last modified 2026-06-17.