logo

QNAP addresses critical flaws across NAS, router software

ID: c7b72fda-943c-5688-aa10-abc9693e5d08

STIX ID: report--c7b72fda-943c-5688-aa10-abc9693e5d08

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-25

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

QNAP published security advisories addressing multiple critical and high-severity vulnerabilities across Notes Station 3, QuRouter, QTS/QuTS Hero, AI Core, and QuLog Center—most notably remote command-injection and authentication bypass flaws (e.g., CVE-2024-38643, CVE-2024-48860) that could enable unauthorized access or remote code execution; QNAP provided fixed versions and urges users to update immediately and avoid exposing devices directly to the Internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.