CVE-2025-47205: QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47205?
CVE-2025-47205 is classified as a high severity vulnerability due to its potential for remote exploitation leading to denial-of-service attacks.
How do I fix CVE-2025-47205?
To fix CVE-2025-47205, ensure your QNAP QTS or QuTS hero software is updated to the latest version available that addresses this vulnerability.
What versions are affected by CVE-2025-47205?
CVE-2025-47205 affects QNAP QTS versions up to 5.2.8.3332 and QuTS hero versions up to h5.2.8.3321.
Can CVE-2025-47205 be exploited remotely?
Yes, CVE-2025-47205 can be exploited remotely if an attacker gains access to an administrator account.
What type of attack can result from CVE-2025-47205?
CVE-2025-47205 can lead to a denial-of-service (DoS) attack against the affected QNAP operating system.