CVE-2025-30267: QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QNAP QTSto a version that resolves this vulnerability.Fixed in 5.2.5.3145 - Upgrade
Upgrade
QNAP QuTS heroto a version that resolves this vulnerability.Fixed in h5.2.5.3138
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30267?
CVE-2025-30267 is considered a high-severity vulnerability due to its potential to allow denial-of-service attacks.
How do I fix CVE-2025-30267?
To fix CVE-2025-30267, users should upgrade their QNAP operating systems to the latest versions released by the vendor.
What systems are affected by CVE-2025-30267?
CVE-2025-30267 affects several versions of QNAP QTS and QuTS hero operating systems.
What can happen if CVE-2025-30267 is exploited?
If exploited, CVE-2025-30267 could allow remote attackers to launch denial-of-service attacks on an affected system.
Who can exploit CVE-2025-30267?
A remote attacker with a user account can exploit CVE-2025-30267 to launch attacks.