SecPod

Learn Search

Search across all Learn content

← Back to Security Research
QNAP Addresses Two Critical Vulnerabilities in QTS Operating System and Applications.

QNAP Addresses Two Critical Vulnerabilities in QTS Operating System and Applications.

QNAP Systems has promptly resolved two critical vulnerabilities, CVE-2023-23368 and CVE-2023-23369, which involved command injection. They were discovered within the QTS operating system and associated applications used on their network-attached storage (NAS) devices. These vulnerabilities could hav...

Nov 6, 2023By Aman Gupta3 min read

QNAP Systems has promptly resolved two critical vulnerabilities, CVE-2023-23368 and CVE-2023-23369, which involved command injection. They were discovered within the QTS operating system and associated applications used on their network-attached storage (NAS) devices. These vulnerabilities could have allowed remote attackers to execute arbitrary commands on affected devices, potentially taking control of them and accessing sensitive data.

The malicious server, which served as the command-and-control center for a botnet of infected devices, was responsible for launching a barrage of brute-force attacks against vulnerable NAS devices. These attacks aimed to gain unauthorized access to the devices by repeatedly attempting to guess weak or default passwords. QNAP’s Product Security Incident Response Team swiftly took action upon detecting the attacks. They effectively blocked hundreds of zombie network IPs, protecting numerous internet-exposed QNAP NAS devices from further assault. Furthermore, they successfully identified the source command-and-control server and, in collaboration with the cloud service provider, took measures to shut it down, preventing the situation from escalating further.

CVE-2023-23368, with a CVSS score of 9.8, represents a critical OS command injection flaw that a remote attacker can exploit to execute commands over a network. According to the advisory, multiple versions of QNAP operating systems are affected by this flaw. If successfully exploited, remote attackers could execute commands through a network.

CVE-2023-23369, rated with a CVSS score of 9.0, shares similarities with the potential for remote attackers to execute commands over a network. This vulnerability, described as an OS command injection issue, affects various QNAP operating systems and applications. It enables remote attackers to execute commands through a network.

“QNAP has released security patches to address these vulnerabilities, and it is urging all users to apply the patches as soon as possible.”

QNAP

Affected Products

The following QNAP operating system versions are affected by CVE-2023-23368:

  • QTS 5.0.x
  • QTS 4.5.x
  • QuTS hero h5.0.x
  • QuTS hero h4.5.x
  • QuTScloud c5.0.x

The following QNAP operating system versions are affected by CVE-2023-23369:

  • QTS 5.1.x
  • QTS 4.3.6
  • QTS 4.3.4
  • QTS 4.3.3
  • QTS 4.2.x
  • Multimedia Console 2.1.x
  • Multimedia Console 1.4.x
  • Media Streaming add-on 500.1.x
  • Media Streaming add-on 500.0.x

Solution

The following fixed versions are available to address CVE-2023-23368:

  • QTS 5.0.1.2376 build 20230421 and later
  • QTS 4.5.4.2374 build 20230416 and later
  • QuTS hero h5.0.1.2376 build 20230421 and later
  • QuTS hero h4.5.4.2374 build 20230417 and later
  • QuTScloud c5.0.1.2374 and later

The following fixed versions are available to address CVE-2023-23369:

  • QTS 5.1.0.2399 build 20230515 and later
  • QTS 4.3.6.2441 build 20230621 and later
  • QTS 4.3.4.2451 build 20230621 and later
  • QTS 4.3.3.2420 build 20230621 and later
  • QTS 4.2.6 build 20230621 and later
  • Multimedia Console 2.1.2 (2023/05/04) and later
  • Multimedia Console 1.4.8 (2023/05/05) and later
  • Media Streaming add-on 500.1.1.2 (2023/06/12) and later
  • Media Streaming add-on 500.0.0.11 (2023/06/16) and later

SanerNow Vulnerability Management and SanerNow Patch Management detect and automatically fix these vulnerabilities by applying security updates. Use SanerNow and keep your systems updated and secure!

Featured Posts

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026

Open CVE-2026-94127: F5 BIG-IP APM Zero-Day Under Active Exploitation
CVE-2026-94127: F5 BIG-IP APM Zero-Day Under Active Exploitation

CVE Research

CVE-2026-94127: F5 BIG-IP APM Zero-Day Under Active Exploitation

Sep 24, 2026

Open No Account Needed: Critical WordPress Flaw (CVE-2026-87902) Lets Attackers Run Code on Some Servers — Patch Now
No Account Needed: Critical WordPress Flaw (CVE-2026-87902) Lets Attackers Run Code on Some Servers — Patch Now

CVE Research

No Account Needed: Critical WordPress Flaw (CVE-2026-87902) Lets Attackers Run Code on Some Servers — Patch Now

WordPress has fixed CVE-2026-87902, an unauthenticated path traversal in page-template resolution that can lead to remote code execution when theme and server conditions align. The issue affects WordPress from 4.7.0 through 7.1.1 and is patched in 7.1.2, with backports across older supported branches. This article covers how the flaw works, affected and fixed versions, impact, and recommended remediation.

Sep 23, 2026

Open Patch Analysis & Exploitation Timeline: Four CVEs, Two Confirmed Zero Days, CISA's September 8, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Four CVEs, Two Confirmed Zero Days, CISA's September 8, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Four CVEs, Two Confirmed Zero Days, CISA's September 8, 2026 KEV Additions

An analysis of four vulnerabilities added to the CISA Known Exploited Vulnerabilities catalog on September 8, 2026, covering public disclosure, patch availability, KEV inclusion, remediation deadlines, vulnerability classes, and patch prioritization considerations.

Sep 22, 2026