CVE-2024-21903: QNAP QTS

Medium severity, CVSS 4.7. EPSS: 0.8% chance of exploitation in the next 30 days.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

Affected products

  • QNAP QTS: version 5.1.0.2348 only; version 5.1.0.2399 only; version 5.1.0.2418 only; version 5.1.0.2444 only; version 5.1.0.2466 only; version 5.1.1.2491 only; …
  • QNAP Quts Hero: version h5.1.0.2409 only; version h5.1.0.2424 only; version h5.1.0.2453 only; version h5.1.0.2466 only; version h5.1.1.2488 only; version h5.1.2.2534 only; …

Published 2024-09-06. Last modified 2026-06-17.