NINTENDO SWITCH Unpetrified: Echoes of Nature Console Release Confirmed for Fall 2026 PHONES Huawei Leads China Smartphone Market as Apple Grows Amid 2% Decline GAMES Phasmophobia Gets Deildegast Ghost and 13 Willow Street Rework STEAM Fallout 76 Update 2.28 Released: Infestations Rebalanced and Boss Loot Fixed GAMES Former Forza Director Calls Xbox Game Pass ‘A Real Shame’ GAMES Bethesda Takes Fallout 76 Servers Offline for July 21 Title Update INTEL Kirin 9030 Pro Teardown Shows SMIC N+3 Beats Intel 18A Pitch PLAYSTATION 5 Wreckreation 2 Announced for PS5, Xbox Series, and PC NINTENDO SWITCH Dear Passengers Console Status: PS, Xbox, PC, and Switch Availability XBOX SERIES X Xbox Game Pass Adds 6 New Games in July 2026, Including Halo GAMES Xbox Game Pass Price Cuts to $22.99 as Seven New Titles Join Service GAMES Hunty Zombie July 2026 Reward Codes: Free Items for Roblox Players GAMES Dear Passengers Release News & Demo Details for 2026 Launch HANDHELD GAMING Anbernic RG SP Launches with GBA SP Design and Thinner Chassis

QNAP Fixes 14 Critical NAS Security Flaws in Latest Update

Daniel Cross 0 comments 2 min read

QNAP released a critical security update addressing 14 vulnerabilities in its NAS operating systems, including QTS and QuTS, urging immediate updates.

QNAP QNAP NAS
SOFTWARE AND UPDATES

QNAP released a critical security update on June 17 to address fourteen vulnerabilities in its network storage operating systems. These flaws range from credential theft risks to arbitrary command execution, posing direct threats to users who store sensitive data on their devices. Administrators must apply these patches immediately to prevent unauthorized access to their network-attached storage units.

Critical flaws include credential theft and command injection risks

The advisory targets the QTS, QuTS hero, QuTS cloud, and QVP operating systems. Specific affected versions include QTS 5.2.7, QuTS hero h5.2.8, QuTS cloud c5.2.8, and QVP 2.7.1. Users running these older builds are exposed to various exploitation methods that could compromise system integrity.

Critical flaws include URL injection vulnerabilities that allow attackers to steal credentials through fake password reset links. Command injection issues enable authenticated administrators to execute arbitrary system commands on the device. A memory vulnerability in the file upload process can be exploited by unauthenticated attackers using manipulated uploads with long filenames.

QNAP has resolved these issues in the latest software releases. The company advises users to update their systems to QTS 5.2.9.3499 or QuTS hero h5.2.9. These fixed versions close the security gaps identified in the advisory and restore full protection for NAS environments.

This update resolves the security gaps identified in advisory QSA-26-10. Users who apply the recommended fixes eliminate the risk of credential theft and unauthorized command execution. Maintaining current operating system versions remains the primary defense against these known vulnerabilities.

Source: NotebookCheck

Discussion

0 comments

Leave a comment