CVE-2025-30272: QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QTSto a version that resolves this vulnerability.Fixed in 5.2.5.3145 - Upgrade
Upgrade
QuTS heroto a version that resolves this vulnerability.Fixed in h5.2.5.3138
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30272?
CVE-2025-30272 is classified as a medium severity vulnerability due to its potential for exploitation leading to denial-of-service (DoS) attacks.
How do I fix CVE-2025-30272?
To fix CVE-2025-30272, you should update your QNAP operating system to QTS version 5.2.5.3145 or later, or QuTS hero version h5.2.5.3138 or later.
What is a NULL pointer dereference in the context of CVE-2025-30272?
A NULL pointer dereference occurs when the software attempts to access or manipulate a memory location that is not assigned, potentially leading to application crashes or DoS.
Which QNAP operating systems are affected by CVE-2025-30272?
CVE-2025-30272 affects several versions of QNAP QTS and QuTS hero operating systems prior to the updated versions mentioned in the advisory.
What could happen if CVE-2025-30272 is exploited?
If CVE-2025-30272 is successfully exploited, it could allow an attacker to launch a denial-of-service (DoS) attack, disrupting the availability of services on the affected QNAP systems.