CVE-2024-21901: QNAP Myqnapcloud

Medium severity, CVSS 4.7. EPSS: 18.7% chance of exploitation in the next 30 days.

A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following versions: myQNAPcloud 1.0.52 ( 2023/11/24 ) and later QTS 4.5.4.2627 build 20231225 and later

Affected products

  • QNAP Myqnapcloud: before 1.0.52 (fixed in 1.0.52)
  • QNAP QTS: before 4.5.4.2627 (fixed in 4.5.4.2627); version 4.5.4.2627 only

Published 2024-03-08. Last modified 2026-06-17.