Executive brief
A security vulnerability has been identified in QNAP storage device operating systems that could allow an attacker to access sensitive system files. To exploit this, an attacker must first obtain administrator-level access to the device. Once authenticated, they could bypass directory restrictions to read internal data, potentially leading to further compromise of the storage system or its data.
Technical details
A path traversal vulnerability (CWE-22) exists in multiple QNAP operating systems, including QTS and QuTS hero. The flaw allows a remote attacker with high privileges (administrator account) to bypass directory access restrictions. By sending specially crafted requests, the attacker can read the contents of files outside of the intended directory, including sensitive system data. The vulnerability is addressed in QTS 5.2.9.3492, QuTS hero h5.2.9.3499, h5.3.4.3500, and h6.0.0.3459.
Affected products
- QNAP QTS 5.2.9.3492 build 20260507 and earlier
- QNAP QuTS hero h5.2.9.3499 build 20260514 and earlier; h5.3.4.3500 build 20260520 and earlier; h6.0.0.3459 build 20260409 and earlier
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory