Vulnerability Database

313,825

Total vulnerabilities in the database

CVE-2024-27124

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network.

We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

  • Published: Apr 26, 2024
  • Updated: Nov 16, 2025
  • CVE: CVE-2024-27124
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CWEs:

OWASP TOP 10:

Software From Fixed in
qnap / qts 4.5.1 4.5.4.2627
qnap / qts 5.0.0 5.1.3.2578
qnap / qts 4.5.4.2627 4.5.4.2627.x
qnap / qts 5.1.3.2578 5.1.3.2578.x
qnap / quts_hero h4.5.0 h4.5.4.2626
qnap / quts_hero h5.0.0 h5.1.3.2578
qnap / quts_hero h4.5.4.2626 h4.5.4.2626.x
qnap / quts_hero h5.1.3.2578 h5.1.3.2578.x
qnap / qutscloud c5.0.0.1919 c5.1.5.2651