CVE-2024-14026

HIGH WAF: High
CVSS 7.8 Published: 2026-03-11
CWE-78

A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.1.9.2954 build 20241120 and later QuTS hero h5.2.3.3006 build 20250108 and later

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
qnapqts5.1.0.2348
qnapqts5.1.0.2399
qnapqts5.1.0.2418
qnapqts5.1.0.2444
qnapqts5.1.0.2466
qnapqts5.1.1.2491
qnapqts5.1.2.2533
qnapqts5.1.3.2578
qnapqts5.1.4.2596
qnapqts5.1.5.2645

References

Back to CVE Database