CVE-2023-41282: QNAP QTS

High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later QuTScloud c5.1.5.2651 and later

Affected products

  • QNAP QTS: version 5.1.0.2348 only; version 5.1.0.2399 only; version 5.1.0.2418 only; version 5.1.0.2444 only; version 5.1.0.2466 only; version 5.1.1.2491 only; …
  • QNAP Quts Hero: version h5.1.0.2409 only; version h5.1.0.2424 only; version h5.1.0.2453 only; version h5.1.0.2466 only; version h5.1.1.2488 only; version h5.1.2.2534 only; …
  • QNAP Qutscloud: version c5.1.0.2498 only

Published 2024-02-02. Last modified 2026-06-17.