PT-2025-35277 · Qnap · Qnap Quts Hero +1

Coral

·

Published

2025-08-29

·

Updated

2025-08-29

·

CVE-2025-30268

CVSS v4.0
5.3
VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Name of the Vulnerable Software and Affected Versions:

QNAP QTS versions prior to 5.2.5.3145 build 20250526

QNAP QuTS hero versions prior to h5.2.5.3138 build 20250519

Description:

A NULL pointer dereference issue exists in QNAP operating systems. A remote attacker gaining a user account can exploit this issue to launch a denial-of-service (DoS) attack.

Recommendations:

Update QTS to version 5.2.5.3145 build 20250526 or later.

Update QuTS hero to version h5.2.5.3138 build 20250519 or later.

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-30268

Affected Products

Qnap Qts
Qnap Quts Hero