Vulnerability record · CVE-2023-47218 · published 13 February 2024
CVE-2023-47218: QNAP QTS and QuTS hero unauthenticated OS command injection
Qnap · Qts
QNAP QTS, QuTS hero and QuTScloud contain an OS command injection flaw reachable over the network without authentication. Successful exploitation lets an attacker run arbitrary commands on the device, which matters because these are internet-facing storage systems holding sensitive data. QNAP has released fixed builds for all three product lines.
Description
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QuTS hero h5.1.5.2647 build 20240118 and later QuTScloud c5.1.5.2651 and later
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Automated analysis
high priorityUnauthenticated network-reachable command injection with a very high EPSS score and public exploit detail, though not yet in KEV or tied to ransomware.
What it is
QNAP QTS, QuTS hero and QuTScloud contain an OS command injection flaw reachable over the network without authentication. Successful exploitation lets an attacker run arbitrary commands on the device, which matters because these are internet-facing storage systems holding sensitive data. QNAP has released fixed builds for all three product lines.
Impact
An attacker gains remote command execution on the NAS with the privileges of the vulnerable service, enabling data theft, configuration changes or use of the device as a foothold. The CVSS scope change indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via the affected QNAP service, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description does not name the specific endpoint or port.
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.8992 (99.8th percentile) and a Rapid7 reference is tagged Exploit, indicating public exploit detail exists. No ransomware group is documented as using it.
What to do
- Upgrade to QTS 5.1.5.2645 build 20240116 or later, QuTS hero h5.1.5.2647 build 20240118 or later, or QuTScloud c5.1.5.2651 or later.
- Do not expose QNAP management or service interfaces directly to the internet; restrict access to trusted networks or a VPN.
- Segment NAS devices from other critical systems and limit outbound traffic to reduce post-exploitation reach.
- Monitor QNAP advisories and apply future security updates promptly.
- Review device logs and accounts for signs of unauthorized command execution or persistence.
Detection
- Alert on unexpected child processes spawned by QNAP web or service daemons, especially shells or command interpreters.
- Monitor for anomalous outbound connections from NAS devices to unfamiliar hosts.
- Audit QNAP authentication and system logs for unusual requests or command-related activity around the affected service.
- Track firmware versions across QTS, QuTS hero and QuTScloud assets and flag any below the fixed builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-23-57 | Vendor Advisory |
| https://www.rapid7.com/blog/post/2024/02/13/cve-2023-47218-qnap-qts-and-quts-hero-unauthenticated-command-injection-fixe | ExploitThird Party Advisory |
| https://www.qnap.com/en/security-advisory/qsa-23-57 | Vendor Advisory |
| https://www.rapid7.com/blog/post/2024/02/13/cve-2023-47218-qnap-qts-and-quts-hero-unauthenticated-command-injection-fixe | ExploitThird Party Advisory |
Track CVE-2023-47218 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-47218), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.