vulnerability

QNAP QTS: CVE-2024-53696: Vulnerability in QuLog Center, Legacy QTS, and Legacy QuTS hero

Severity
6
CVSS
(AV:N/AC:L/Au:M/C:C/I:N/A:N)
Published
Mar 8, 2025
Added
Aug 4, 2025
Modified
Dec 8, 2025

Description

A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center and legacy versions of QTS and QuTS hero. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data.

Solution

qnap-qts-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.