Improper Auth in QNAP NAS Allows Remote Compromise
CVE-2024-38639 Published on September 18, 2026
QTS
An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system.
QTS is not affected.
We have already fixed the vulnerability in the following version:
Vulnerability Analysis
CVE-2024-38639 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an authentification Vulnerability?
When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
CVE-2024-38639 has been classified to as an authentification vulnerability or weakness.
Products Associated with CVE-2024-38639
Want to know whenever a new CVE is published for QNAP Qts? stack.watch will email you.