CVE-2023-45025: QNAP QTS
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.4.2596 build 20231128 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
Affected products
- QNAP QTS: version 4.5.4.1715 only; version 4.5.4.1723 only; version 4.5.4.1741 only; version 4.5.4.1787 only; version 4.5.4.1800 only; version 4.5.4.1892 only; …
- QNAP Quts Hero: version h4.5.4.1771 only; version h4.5.4.1800 only; version h4.5.4.1813 only; version h4.5.4.1848 only; version h4.5.4.1892 only; version h4.5.4.1951 only; …
- QNAP Qutscloud: version c5.1.0.2498 only
Published 2024-02-02. Last modified 2026-06-17.