CVE-2024-32766
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We ha...
Affects 3 products across 1 vendor.
Attacker injects operating system commands through application inputs passed to a shell or system call.
Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.
Show all 11
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical OS command injection vulnerability affects certain QNAP operating system versions, allowing remote command execution.
BSID: BS-2024-GLOBAL-192333-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2024-32766?
What is the CVSS score for CVE-2024-32766?
Is CVE-2024-32766 actively exploited?
How do I remediate CVE-2024-32766?
What systems are affected by CVE-2024-32766?
| CVE ID | CVE-2024-32766 |
|---|---|
| BSID | BS-2024-GLOBAL-192333-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2024-04-26 |
| Last Modified | 2025-12-10 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Source | NVD |
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
Source: NIST NVD / MITRE CVE Database
The vulnerability can be exploited by an attacker to execute arbitrary OS commands via a network interface, potentially leading to unauthorized access and system compromise.
Exploitation Likelihood: CRITICAL
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 6d06f1305a9fd61776ee891e350e07505ebf0ed93aa5b700b65d7aa54bf74ffb59d2a40e4ab8c4b8f99ee5c7b28c758f2aef797b3af2f79822e239b0497c3683 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →