CVE-2025-29882: QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QTSto a version that resolves this vulnerability.Fixed in 5.2.5.3145 - Upgrade
Upgrade
QuTS heroto a version that resolves this vulnerability.Fixed in h5.2.5.3138
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29882?
CVE-2025-29882 has a high severity rating due to its potential to cause a denial-of-service attack via a NULL pointer dereference.
How do I fix CVE-2025-29882?
To fix CVE-2025-29882, update your QNAP QTS to version 5.2.5.3145 or QNAP QuTS hero to h5.2.5.3138 or later.
What versions are affected by CVE-2025-29882?
CVE-2025-29882 affects QNAP QTS up to version 5.2.5.3145 and QNAP QuTS hero up to version h5.2.5.3138.
Can CVE-2025-29882 be exploited remotely?
Yes, a remote attacker with user account access can exploit CVE-2025-29882 to perform denial-of-service attacks.
What is the impact of CVE-2025-29882?
The impact of CVE-2025-29882 is a denial-of-service condition that can disrupt the availability of the affected QNAP systems.