QNAP QuLog Center, Legacy QTS, and QuTS hero Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability exists in QuLog Center, as well as in legacy versions of QTS and QuTS hero. This vulnerability allows remote attackers with administrator access to read application data. The issue has been addressed in QuLog Center versions 1.7.0.829 and 1.8.0.888, as well as in QTS 4.5.4.2957 and QuTS hero h4.5.4.2956, all released in October 2024.

Impact

Exploitation of this vulnerability could lead to unauthorized access to application data by remote attackers with administrator privileges.

Remediation

Users are advised to update QuLog Center and their operating system to the latest versions. Instructions for updating QuLog Center and QTS or QuTS hero are available on the QNAP website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
3.3
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.