← Vulnerability feed

Vulnerability record · CVE-2023-47218 · published 13 February 2024

CVE-2023-47218: QNAP QTS and QuTS hero unauthenticated OS command injection

Qnap · Qts

QNAP QTS, QuTS hero and QuTScloud contain an OS command injection flaw reachable over the network without authentication. Successful exploitation lets an attacker run arbitrary commands on the device, which matters because these are internet-facing storage systems holding sensitive data. QNAP has released fixed builds for all three product lines.

8.3 CVSS 3.1 High EPSS 90% · top 0.2% CWE-77 · Command injectionCWE-78 · OS command injection
8.3CVSS 3.1 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QuTS hero h5.1.5.2647 build 20240118 and later QuTScloud c5.1.5.2651 and later

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable command injection with a very high EPSS score and public exploit detail, though not yet in KEV or tied to ransomware.

What it is

QNAP QTS, QuTS hero and QuTScloud contain an OS command injection flaw reachable over the network without authentication. Successful exploitation lets an attacker run arbitrary commands on the device, which matters because these are internet-facing storage systems holding sensitive data. QNAP has released fixed builds for all three product lines.

Impact

An attacker gains remote command execution on the NAS with the privileges of the vulnerable service, enabling data theft, configuration changes or use of the device as a foothold. The CVSS scope change indicates impact can extend beyond the vulnerable component.

Attack surface

Reached over the network via the affected QNAP service, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description does not name the specific endpoint or port.

Exploitation

Not listed in CISA KEV, but EPSS is very high at 0.8992 (99.8th percentile) and a Rapid7 reference is tagged Exploit, indicating public exploit detail exists. No ransomware group is documented as using it.

What to do

  • Upgrade to QTS 5.1.5.2645 build 20240116 or later, QuTS hero h5.1.5.2647 build 20240118 or later, or QuTScloud c5.1.5.2651 or later.
  • Do not expose QNAP management or service interfaces directly to the internet; restrict access to trusted networks or a VPN.
  • Segment NAS devices from other critical systems and limit outbound traffic to reduce post-exploitation reach.
  • Monitor QNAP advisories and apply future security updates promptly.
  • Review device logs and accounts for signs of unauthorized command execution or persistence.

Detection

  • Alert on unexpected child processes spawned by QNAP web or service daemons, especially shells or command interpreters.
  • Monitor for anomalous outbound connections from NAS devices to unfamiliar hosts.
  • Audit QNAP authentication and system logs for unusual requests or command-related activity around the affected service.
  • Track firmware versions across QTS, QuTS hero and QuTScloud assets and flag any below the fixed builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-47218 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-2509QNAP QTS and QuTS hero command injectionQTS and QuTS hero contain a command injection flaw that lets an attacker run arbitrary commands within a compromised application. It is remotely reac…KEVEPSS 34%analysed9.8CVE-2018-19949QNAP QTS File Station command injection allows remote code executionQNAP QTS contains a command injection flaw in File Station that lets remote attackers run arbitrary commands on the NAS. It is remotely reachable wit…KEVEPSS 28%analysed9.8CVE-2019-7193QNAP QTS improper input validation allows remote code injectionQNAP QTS contains an improper input validation flaw that lets remote attackers inject arbitrary code into the system. It is remotely reachable withou…KEVEPSS 14%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed6.1CVE-2018-19953QNAP QTS File Station cross-site scripting flawQNAP QTS contains a cross-site scripting vulnerability in File Station that lets remote attackers inject malicious code. It matters because the flaw …KEVEPSS 29%analysed5.4CVE-2018-19943QNAP QTS File Station cross-site scriptingQNAP QTS contains a cross-site scripting flaw in File Station that lets a remote attacker inject malicious code. It matters because the vendor has fi…KEVEPSS 21%analysed10.0CVE-2024-32766Qnap qts command injection vulnerabilityAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2023-47218), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.