CVE-2025-30274: QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QNAP QTSto a version that resolves this vulnerability.Fixed in 5.2.5.3145 - Upgrade
Upgrade
QNAP QuTS heroto a version that resolves this vulnerability.Fixed in h5.2.5.3138
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30274?
CVE-2025-30274 is a critical vulnerability that can lead to a denial-of-service (DoS) attack.
How do I fix CVE-2025-30274?
To fix CVE-2025-30274, update your QNAP operating system to QTS version 5.2.5.3145 or higher, or QuTS hero version 5.2.5.3138 or higher.
Which QNAP products are affected by CVE-2025-30274?
CVE-2025-30274 affects QNAP QTS versions up to 5.2.5.3145 and QuTS hero versions up to 5.2.5.3138.
What type of vulnerability is CVE-2025-30274?
CVE-2025-30274 is a NULL pointer dereference vulnerability.
Can CVE-2025-30274 be exploited remotely?
Yes, CVE-2025-30274 can potentially be exploited remotely to perform a denial-of-service attack.