VYPR
Unrated severityNVD Advisory· Published Feb 2, 2024· Updated Jun 17, 2025

QTS, QuTS hero, QuTScloud

CVE-2023-45037

Description

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.

We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTScloud c5.1.5.2651 and later

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer copy without size check in QNAP QTS, QuTS hero, and QuTScloud allows authenticated administrators to execute code via network.

Vulnerability

CVE-2023-45037 is a buffer copy without checking size of input vulnerability in QNAP operating systems, including QTS 5.1.x, QuTS hero h5.1.x, and QuTScloud 5.x. The flaw resides in a component that processes network input, where a fixed-size buffer is used without validating the length of the source data, leading to a buffer overflow condition. The vulnerability is exploitable only by authenticated administrators who have network access to the device [1].

Exploitation

An attacker must first obtain administrative credentials for the affected QNAP device. With those credentials, the attacker can send a specially crafted network request that exceeds the expected buffer size. The request triggers a buffer copy operation that overflows the destination buffer, potentially corrupting adjacent memory. The exact sequence of steps involves authenticating as an administrator, then sending the malicious payload over the network to the vulnerable service [1].

Impact

Successful exploitation allows the authenticated administrator to execute arbitrary code on the device. This could lead to full compromise of the NAS, including data exfiltration, further lateral movement within the network, or persistent control of the device. The impact is limited to authenticated users, but the attacker gains code execution privileges at the system level [1].

Mitigation

QNAP has fixed the vulnerability in QTS 5.1.4.2596 build 20231128 and later, QuTS hero h5.1.4.2596 build 20231128 and later, and QuTScloud c5.1.5.2651 and later. Users should update to these or newer versions via the Control Panel Firmware Update or by downloading from the QNAP website. No workarounds are available, and the vulnerability is not currently listed in CISA KEV [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

6
  • Qnap/Qtsllm-fuzzy
    Range: <5.1.3.2578
  • Qnap/QuTS herollm-fuzzy
    Range: <h5.1.3.2578
  • Qnap/QuTScloudllm-fuzzy
    Range: <c5.1.5.2651
  • QNAP Systems Inc./QTSv5
    Range: 5.1.x
  • QNAP Systems Inc./QuTScloudv5
    Range: c5.x.x
  • QNAP Systems Inc./QuTS herov5
    Range: h5.1.x

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.