An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.2.1566 Build 20210202. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638 build 20210414. This issue does not affect: QNAP Systems Inc. QTS 4.5.3.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2020-23758 | An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.2.1566 Build 20210202. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638 build 20210414. This issue does not affect: QNAP Systems Inc. QTS 4.5.3. |
Fixes
Solution
QNAP have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QuTS hero h4.5.2.1638 build 20210414 and later
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.qnap.com/zh-tw/security-advisory/qsa-21-32 |
![]() ![]() |
History
Sat, 12 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-09-17T02:01:31.559Z
Reserved: 2021-01-19T00:00:00
Link: CVE-2020-36194

No data.

Status : Modified
Published: 2021-07-01T02:15:07.157
Modified: 2024-11-21T05:28:59.373
Link: CVE-2020-36194

No data.

No data.