CVE-2024-32766

CRITICAL

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We ha...

Affects 3 products across 1 vendor.

BCS7.69
CVSS 3.110.0
EPSS2.3%
Percentile82th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-77: Command Injection

Attacker injects operating system commands through application inputs passed to a shell or system call.

CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-77 CWE-78
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-77
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-77 CWE-78
Show all 11
via CWE-77
via CWE-77
via CWE-78
via CWE-77
via CWE-77
via CWE-77

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical OS command injection vulnerability affects certain QNAP operating system versions, allowing remote command execution.

BSID: BS-2024-GLOBAL-192333-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-32766?
A critical OS command injection vulnerability affects certain QNAP operating system versions, allowing remote command execution.
What is the CVSS score for CVE-2024-32766?
CVE-2024-32766 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 2.3%.
Is CVE-2024-32766 actively exploited?
No confirmed active exploitation of CVE-2024-32766 as of 2026-05-30.
How do I remediate CVE-2024-32766?
Priority: IMMEDIATE. Advisory: https://www.qnap.com/en/security-advisory/qsa-24-09 PSIRT: [email protected]
What systems are affected by CVE-2024-32766?
CVE-2024-32766 affects: Qnap, Qnap, Qnap.
Vulnerability Details
CVE IDCVE-2024-32766
BSIDBS-2024-GLOBAL-192333-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2024-04-26
Last Modified2025-12-10
ICS Relevance70%
Weakness (CWE)
SourceNVD
Official Description

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h5.1.3.2578 build 20231110 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited by an attacker to execute arbitrary OS commands via a network interface, potentially leading to unauthorized access and system compromise.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Qnap Qts
Qnap Quts Hero
Qnap Qutscloud
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 830 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash6d06f1305a9fd61776ee891e350e07505ebf0ed93aa5b700b65d7aa54bf74ffb59d2a40e4ab8c4b8f99ee5c7b28c758f2aef797b3af2f79822e239b0497c3683
Related CVEs affecting Qnap
CVE-2017-7876 10.0 This command injection vulnerability in QTS allows attackers to run arbitrary... CVE-2024-32764 9.9 A missing authentication for critical function vulnerability has been reporte... CVE-2024-21899 9.8 An improper authentication vulnerability has been reported to affect several ... CVE-2025-59385 9.8 An authentication bypass by spoofing vulnerability has been reported to affec... CVE-2021-38684 9.8 A stack buffer overflow vulnerability has been reported to affect QNAP NAS ru...
View all Qnap CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →