CVE-2023-41290: QNAP Qufirewall

Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.

A path traversal vulnerability has been reported to affect QuFirewall. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: QuFirewall 2.4.1 ( 2024/02/01 ) and later

Affected products

  • QNAP Qufirewall: version 2.4.0 only

Published 2024-04-26. Last modified 2026-06-17.