PT-2025-46144 · Qnap · Qnap Quts Hero H5.2.7+2

Le Mau Anh Phong

·

Published

2025-11-08

·

Updated

2026-03-18

·

CVE-2025-62848

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QNAP QTS versions prior to 5.2.7.3297 build 20251024 QNAP QuTS hero h5.2.7 versions prior to 5.2.7.3297 build 20251024 QNAP QuTS hero h5.3.1 versions prior to 5.3.1.3292 build 20251024
Description A flaw exists due to a NULL pointer dereference. This can allow a remote attacker to cause a denial-of-service (DoS) condition.
Recommendations Update QTS to version 5.2.7.3297 build 20251024 or later. Update QuTS hero h5.2.7 to version 5.2.7.3297 build 20251024 or later. Update QuTS hero h5.3.1 to version 5.3.1.3292 build 20251024 or later.

Fix

RCE

DoS

Use After Free

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-16031
CVE-2025-62848
ZDI-26-199

Affected Products

Qnap Qts
Qnap Quts Hero H5.2.7
Qnap Quts Hero H5.3.1