vulnerability
QNAP QTS: CVE-2020-36194: XSS Vulnerability in QTS and QuTS hero
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:M/Au:N/C:N/I:P/A:N) | Jul 1, 2021 | Aug 4, 2025 | Oct 16, 2025 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Jul 1, 2021
Added
Aug 4, 2025
Modified
Oct 16, 2025
Description
An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QuTS hero h4.5.2.1638 build 20210414 and later QNAP NAS running QTS 4.5.3 and later are not affected.
Solution
qnap-qts-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.