vulnerability
QNAP QTS: CVE-2022-27598: Vulnerabilities in QTS, QuTS hero, QuTScloud, and QVP
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 3 | (AV:N/AC:L/Au:M/C:P/I:N/A:N) | Mar 30, 2023 | Aug 4, 2025 | Mar 25, 2026 |
Severity
3
CVSS
(AV:N/AC:L/Au:M/C:P/I:N/A:N)
Published
Mar 30, 2023
Added
Aug 4, 2025
Modified
Mar 25, 2026
Description
Two vulnerabilities have been reported to affect multiple QNAP operating systems. If exploited, these vulnerabilities allow remote authenticated administrators to get secret values. The vulnerabilities affect the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already fixed the vulnerabilities in the following operating system versions: QTS 5.0.1.2346 build 20230322 and later QuTS hero h5.0.1.2348 build 20230324 and later QNAP is urgently fixing the vulnerabilities in QuTScloud and QVP. Please check this security advisory regularly for updates and promptly update your operating system to the latest recommended version as soon as it is available.
Solution
qnap-qts-upgrade-latest
References
- CWE-125
- CVE-2022-27598
- https://attackerkb.com/topics/CVE-2022-27598
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27598
- https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2022-27598
- https://www.qnap.com/en-uk/security-advisory/QSA-23-06
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-32099
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.