CVE-2025-30273: QTS, QuTS hero
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory.
We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QNAP QTSto a version that resolves this vulnerability.Fixed in 5.2.5.3145 - Upgrade
Upgrade
QNAP QuTS heroto a version that resolves this vulnerability.Fixed in h5.2.5.3138
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30273?
CVE-2025-30273 is classified as a high severity out-of-bounds write vulnerability.
How do I fix CVE-2025-30273?
To fix CVE-2025-30273, update your QNAP operating system to version 5.2.5.3145 for QTS or h5.2.5.3138 for QuTS hero.
What are the potential impacts of exploiting CVE-2025-30273?
Exploitation of CVE-2025-30273 can lead to memory corruption or modification, compromising system integrity.
Which versions of QNAP are affected by CVE-2025-30273?
CVE-2025-30273 affects several versions of QNAP QTS and QuTS hero prior to the specified secure versions.
Can the CVE-2025-30273 vulnerability be exploited remotely?
Yes, CVE-2025-30273 can be exploited remotely if the attacker has a valid user account.