6.5

CVE-2025-62852

QTS, QuTS hero

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes.

We have already fixed the vulnerability in the following version:
QTS 5.2.8.3332 build 20251128 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QnapQts Version5.2.0.2737 Updatebuild_20240417
QnapQts Version5.2.0.2744 Updatebuild_20240424
QnapQts Version5.2.0.2782 Updatebuild_20240601
QnapQts Version5.2.0.2802 Updatebuild_20240620
QnapQts Version5.2.0.2823 Updatebuild_20240711
QnapQts Version5.2.0.2851 Updatebuild_20240808
QnapQts Version5.2.0.2860 Updatebuild_20240817
QnapQts Version5.2.1.2930 Updatebuild_20241025
QnapQts Version5.2.2.2950 Updatebuild_20241114
QnapQts Version5.2.3.3006 Updatebuild_20250108
QnapQts Version5.2.4.3070 Updatebuild_20250312
QnapQts Version5.2.4.3079 Updatebuild_20250321
QnapQts Version5.2.4.3092 Updatebuild_20250403
QnapQts Version5.2.5.3145 Updatebuild_20250526
QnapQts Version5.2.6.3195 Updatebuild_20250715
QnapQts Version5.2.6.3229 Updatebuild_20250818
QnapQts Version5.2.7.3256 Updatebuild_20250913
QnapQts Version5.2.7.3297 Updatebuild_20251024
QnapQuts Hero Versionh5.2.0.2737 Updatebuild_20240417
QnapQuts Hero Versionh5.2.0.2782 Updatebuild_20240601
QnapQuts Hero Versionh5.2.0.2789 Updatebuild_20240607
QnapQuts Hero Versionh5.2.0.2802 Updatebuild_20240620
QnapQuts Hero Versionh5.2.0.2823 Updatebuild_20240711
QnapQuts Hero Versionh5.2.0.2851 Updatebuild_20240808
QnapQuts Hero Versionh5.2.0.2860 Updatebuild_20240817
QnapQuts Hero Versionh5.2.1.2929 Updatebuild_20241025
QnapQuts Hero Versionh5.2.1.2940 Updatebuild_20241105
QnapQuts Hero Versionh5.2.2.2952 Updatebuild_20241116
QnapQuts Hero Versionh5.2.3.3006 Updatebuild_20250108
QnapQuts Hero Versionh5.2.4.3070 Updatebuild_20250312
QnapQuts Hero Versionh5.2.4.3079 Updatebuild_20250321
QnapQuts Hero Versionh5.2.5.3138 Updatebuild_20250519
QnapQuts Hero Versionh5.2.6.3195 Updatebuild_20250715
QnapQuts Hero Versionh5.2.7.3256 Updatebuild_20250913
QnapQuts Hero Versionh5.2.7.3297 Updatebuild_20251024
QnapQuts Hero Versionh5.3.0.3115 Updatebuild_20250430
QnapQuts Hero Versionh5.3.0.3145 Updatebuild_20250530
QnapQuts Hero Versionh5.3.0.3192 Updatebuild_20250716
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.38
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 1.2 5.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
security@qnapsecurity.com.tw 1.2 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.