PT-2025-46145 · Qnap · Qts+1

Le Mau Anh Phong

·

Published

2025-11-08

·

Updated

2026-03-16

·

CVE-2025-62849

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QNAP QTS versions prior to 5.2.7.3297 build 20251024 QNAP QuTS hero versions prior to h5.2.7.3297 build 20251024 QNAP QuTS hero versions prior to h5.3.1.3292 build 20251024
Description An SQL injection flaw exists in QNAP NAS devices running QTS and QuTS hero operating systems. Successful exploitation of this issue could allow a remote attacker to execute unauthorized code and potentially compromise the device. The vulnerability allows attackers to execute unauthorized code or commands.
Recommendations Update QTS to version 5.2.7.3297 build 20251024 or later. Update QuTS hero to version h5.2.7.3297 build 20251024 or later. Update QuTS hero to version h5.3.1.3292 build 20251024 or later.

Fix

RCE

Use After Free

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-16028
CVE-2025-62849
ZDI-26-200

Affected Products

Qts
Quts Hero