CVE-2023-32969: QNAP QTS

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later

Affected products

  • QNAP QTS: from 5.1.0, before 5.1.4.2596 (fixed in 5.1.4.2596); version 5.1.4.2596 only
  • QNAP Quts Hero: from h5.1.0, before h5.1.4.2596 (fixed in h5.1.4.2596); version h5.1.4.2596 only
  • QNAP Qutscloud: from c5.0.0.1919, before c5.1.5.2651 (fixed in c5.1.5.2651)

Published 2024-03-08. Last modified 2026-06-17.