logo

QNAP Patches 14 Vulnerabilities in QTS, QuTS hero, and QVP Devices

ID: 9ebc89fc-42fe-5c3c-9906-ab9995c4a427

STIX ID: report--9ebc89fc-42fe-5c3c-9906-ab9995c4a427

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-21

Date Updated: 2026-06-21

Author: Do Son

...
...

**TL;DR:** QNAP released patches for 14 vulnerabilities across QTS, QuTS hero, QuTS cloud, and QVP — including multiple command-injection flaws, a URL-injection credential theft bug (CVE-2025-59382), pre-auth NULL-pointer and other denial-of-service issues, and buffer overflows; most require authentication but some are exploitable without login. Administrators should apply the published firmware updates, restrict admin access, keep management interfaces off the public internet, and maintain offline backups and snapshots.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.