CVE-2023-41282: QTS, QuTS hero, QuTScloud
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.
We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later QuTScloud c5.1.5.2651 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41282?
CVE-2023-41282 has been classified as a critical vulnerability due to its potential for OS command injection affecting several QNAP operating systems.
How do I fix CVE-2023-41282?
To mitigate CVE-2023-41282, update your QNAP operating system to one of the patched versions provided by QNAP.
Who is affected by CVE-2023-41282?
CVE-2023-41282 affects authenticated administrators of multiple QNAP operating system versions that did not apply the recommended updates.
Can CVE-2023-41282 be exploited remotely?
Yes, CVE-2023-41282 can be exploited remotely by authenticated administrators through the network.
When was CVE-2023-41282 disclosed?
CVE-2023-41282 was disclosed in 2023 as part of QNAP's ongoing security advisories.