VYPR
Medium severity4.3NVD Advisory· Published Mar 8, 2024· Updated Jun 17, 2026

CVE-2024-21900

CVE-2024-21900

Description

An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network.

We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTScloud c5.1.5.2651 and later

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

11
  • Qnap/Qts3 versions
    cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*range: <5.1.3.2578
    • cpe:2.3:o:qnap:qts:5.1.3.2578:-:*:*:*:*:*:*
    • (no CPE)range: before 5.1.3.2578 build 20231110
  • Qnap/Quts Hero3 versions
    cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*range: <h5.1.3.2578
    • cpe:2.3:o:qnap:quts_hero:h5.1.3.2578:-:*:*:*:*:*:*
    • (no CPE)range: before h5.1.3.2578 build 20231110
  • Qnap/QuTScloud2 versions
    cpe:2.3:o:qnap:qutscloud:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:qnap:qutscloud:*:*:*:*:*:*:*:*range: <c5.1.5.2651
    • (no CPE)range: before c5.1.5.2651
  • Range: 5.1.x
  • Range: h5.1.x
  • Range: c5.x.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.