Description
An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system.
QTS is not affected.

We have already fixed the vulnerability in the following version:
Published: 2026-09-18
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper Authentication
Action: Confirm Unaffected
AI Analysis

Impact

This vulnerability is an improper authentication flaw that allows remote attackers to exploit the system and compromise its security. The flaw undermines the integrity of the authentication process, potentially granting unauthorized access to device controls. The impact includes loss of confidentiality, integrity, or availability if an attacker gains unauthorized authority.

Affected Systems

The advisory explicitly indicates that QTS is not affected. No other specific products or firmware versions are identified in the official announcement, so at present the scope of impact is unknown beyond this clarification.

Risk and Exploitability

The CVSS base score is 4.8, indicating a medium severity. The EPSS score is less than 1 %, signifying a low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers would need remote network access to the device’s management interface to attempt exploitation, and no public exploit code has been documented. Given the moderate severity and low exploitation probability, the overall risk remains moderate but warrants timely remediation.

Generated by OpenCVE AI on September 19, 2026 at 21:28 UTC.

Remediation

Vendor Solution

We have already fixed the vulnerability in the following version:


OpenCVE Recommended Actions

  • Review the QNAP Security Advisory to confirm whether your device is affected and, if so, upgrade to the patched firmware version.
  • Limit external network access to the device’s management interfaces and use network segmentation to isolate the device.
  • Enforce strong password policies and, where supported, enable multi‑factor authentication to reduce the risk of credential compromise.

Generated by OpenCVE AI on September 19, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Qnap
Qnap qts
Vendors & Products Qnap
Qnap qts

Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system. QTS is not affected. We have already fixed the vulnerability in the following version:
Title QTS
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2026-09-18T14:31:44.689Z

Reserved: 2024-06-19T00:17:01.279Z

Link: CVE-2024-38639

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:07.312Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:49.293

Modified: 2026-09-28T14:10:00.213

Link: CVE-2024-38639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:30:16Z

Weaknesses