CVE-2024-14026 PUBLISHED

QTS, QuTS hero

Assigner: qnap
Reserved: 09.03.2026 Published: 11.03.2026 Updated: 11.03.2026

A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands.

We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.3.3006 build 20250108 and later

Metrics

CVSS Vector: CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
CVSS Score: 2

Product Status

Vendor QNAP Systems Inc.
Product QTS
Versions Default: unaffected
  • affected from 5.1.x to 5.1.9.2954 build 20241120 (excl.)
  • affected from 5.2.x to 5.2.3.3006 build 20250108 (excl.)
Vendor QNAP Systems Inc.
Product QuTS hero
Versions Default: unaffected
  • affected from h5.1.x to h5.1.9.2954 build 20241120 (excl.)
  • affected from h5.2.x to h5.2.3.3006 build 20250108 (excl.)

Solutions

We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.3.3006 build 20250108 and later

References

Problem Types

  • CWE-78 CWE

Impacts

  • CAPEC-88