CVE-2023-41281: QTS, QuTS hero, QuTScloud
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later QuTScloud c5.1.5.2651 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41281?
CVE-2023-41281 is classified as a high severity OS command injection vulnerability.
How do I fix CVE-2023-41281?
To fix CVE-2023-41281, update your QNAP device to one of the patched versions listed in the security advisory.
Who is affected by CVE-2023-41281?
CVE-2023-41281 affects authenticated administrators of several QNAP operating system versions.
What are the versions affected by CVE-2023-41281?
The affected versions include QTS versions before 5.1.4.2596 and various builds of QuTS hero.
Can CVE-2023-41281 be exploited remotely?
Yes, CVE-2023-41281 can be exploited remotely if an attacker has authenticated access.