Qnap · Qnap Qts · CVE-2024-21906
**Name of the Vulnerable Software and Affected Versions**
QNAP QTS versions prior to 5.1.8.2823 build 20240712
QNAP QuTS hero versions prior to h5.1.8.2823 build 20240712
**Description**
An OS command injection issue has been reported to affect several QNAP operating system versions. If exploited, the issue could allow authenticated administrators to execute commands via a network.
**Recommendations**
For QNAP QTS versions prior to 5.1.8.2823 build 20240712, update to QTS 5.1.8.2823 build 20240712 or later.
For QNAP QuTS hero versions prior to h5.1.8.2823 build 20240712, update to QuTS hero h5.1.8.2823 build 20240712 or later.