CVE-2025-22481: QTS, QuTS hero
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to execute arbitrary commands.
We have already fixed the vulnerability in the following versions: QTS 5.2.4.3079 build 20250321 and later QuTS hero h5.2.4.3079 build 20250321 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22481?
CVE-2025-22481 is classified as a high-severity command injection vulnerability affecting QNAP operating systems.
How do I fix CVE-2025-22481?
To fix CVE-2025-22481, upgrade to QNAP QTS version 5.2.4.3079 or QuTS hero version h5.2.4.3079 or later.
Who is affected by CVE-2025-22481?
CVE-2025-22481 affects users of QNAP QTS and QuTS hero prior to the specified fixed versions.
What type of attacks can exploit CVE-2025-22481?
CVE-2025-22481 allows remote attackers with user access to execute arbitrary commands on the affected systems.
When was CVE-2025-22481 reported?
CVE-2025-22481 was reported recently and details were disclosed by QNAP in a security advisory.