Executive brief
QNAP QTS contains an improper input validation vulnerability that allows remote attackers to inject arbitrary code into the system. The vulnerability has been observed being exploited in the wild and affects multiple versions of the QTS operating system.
Affected products
- QNAP Systems QTS 4.3.6.0895 through 4.3.6.1033, 4.4.1.0948 through 4.4.1.1033 (beta)
Timeline
- 2019-11-25: advisory: Vendor advisory published by QNAP (NAS-201911-25)
- 2019-12-10: disclosed: Initial NVD analysis and CVSS scoring
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-06-08: other: Vulnerability published to NVD