CVE-2023-41291: QNAP Qufirewall

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

A path traversal vulnerability has been reported to affect QuFirewall. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: QuFirewall 2.4.1 ( 2024/02/01 ) and later

Affected products

  • QNAP Qufirewall: before 2.4.1 (fixed in 2.4.1)

Published 2024-04-26. Last modified 2026-06-17.