# QNAP Systems

QNAP Systems (qnap.com): subprocessors, data processing agreement, security documents and changes, as monitored by Third Party Index.

- Page: https://thirdpartyindex.com/vendors/qnap-systems
- Documents last verified: 2026-10-07
- Transparency rating: 38/100 (how much it publishes, not how secure it is): Subprocessor list 0/30 (not found); Processing locations 0/8 (no list); Purposes 0/7 (no list); Data processing addendum 0/12 (not found); Trust center 8/8; Privacy policy 6/6; security.txt 6/6; Security page 5/5; Status page 0/5 (not found); Vulnerability disclosure 5/5; Pages still reachable 8/8
- Cite as: QNAP Systems, Third Party Index, https://thirdpartyindex.com/vendors/qnap-systems (data CC BY 4.0)

## Documents

| Document | URL | Last verified | Last changed |
|---|---|---|---|
| Trust center | https://www.qnap.com/en-us/solution/trust-center | 2026-10-07 | 2026-10-02 |
| Privacy policy | https://www.qnap.com/en-us/legal/qnap-privacy-policy | 2026-10-07 | 2026-09-27 |
| Terms | https://www.qnap.com/en-us/legal/qnap-website-terms-of-use | 2026-10-07 | 2026-10-05 |
| Security page | https://www.qnap.com/en-us/security/ | 2026-10-07 | 2026-09-27 |
| security.txt | https://www.qnap.com/.well-known/security.txt | 2026-10-07 | 2026-09-27 |
| Security advisories | https://www.qnap.com/en-us/security-advisories/ | 2026-10-07 | 2026-09-27 |

## Subprocessors (0)

No subprocessor list has been found or read for this vendor.

## Subprocessor of (0)

No tracked vendor lists it.

## Security record

CISA's Known Exploited Vulnerabilities catalog lists 11 vulnerabilities in its software:

- CVE-2023-47565 (VioStor NVR), listed 2023-12-21: QNAP VioStor NVR OS Command Injection Vulnerability
- CVE-2022-27593 (Photo Station), listed 2022-09-08: QNAP Photo Station Externally Controlled Reference Vulnerability (known ransomware use)
- CVE-2019-7192 (Photo Station), listed 2022-06-08: QNAP Photo Station Improper Access Control Vulnerability (known ransomware use)
- CVE-2019-7193 (QTS), listed 2022-06-08: QNAP QTS Improper Input Validation Vulnerability (known ransomware use)
- CVE-2019-7194 (Photo Station), listed 2022-06-08: QNAP Photo Station Path Traversal Vulnerability (known ransomware use)
- CVE-2019-7195 (Photo Station), listed 2022-06-08: QNAP Photo Station Path Traversal Vulnerability (known ransomware use)
- CVE-2018-19943 (Network Attached Storage (NAS)), listed 2022-05-24: QNAP NAS File Station Cross-Site Scripting Vulnerability (known ransomware use)
- CVE-2018-19949 (Network Attached Storage (NAS)), listed 2022-05-24: QNAP NAS File Station Command Injection Vulnerability (known ransomware use)
- CVE-2018-19953 (Network Attached Storage (NAS)), listed 2022-05-24: QNAP NAS File Station Cross-Site Scripting Vulnerability (known ransomware use)
- CVE-2020-2509 (QNAP Network-Attached Storage (NAS)), listed 2022-04-11: QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
- CVE-2021-28799 (Network Attached Storage (NAS)), listed 2022-03-31: QNAP NAS Improper Authorization Vulnerability (known ransomware use)

## Security contact

From its security.txt (https://www.qnap.com/.well-known/security.txt) ([evidence](https://thirdpartyindex.com/evidence/10831)):

- Contact: mailto:security@qnap.com
- Disclosure policy: https://www.qnap.com/en/security-bounty-program
- Encryption key: https://www.qnap.com/.well-known/pgp-key.txt
- Acknowledgments: https://www.qnap.com/en/security-bounty-program
- Languages: en, zh-Hant
- Valid until 2027-08-12

---

Third Party Index (https://thirdpartyindex.com) monitors vendors' public security and privacy documents and keeps each version as evidence. Data CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/); vendors' own documents are theirs. API: https://thirdpartyindex.com/api
