CVE-2025-47208: QTS, QuTS hero
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.
We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.2.6.3195 build 20250715 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47208?
CVE-2025-47208 is considered a moderate severity vulnerability due to its potential impact on resource allocation.
How does CVE-2025-47208 affect QNAP systems?
CVE-2025-47208 allows a remote attacker with user account access to exhaust system resources, affecting overall performance.
How do I fix CVE-2025-47208?
To fix CVE-2025-47208, update your QNAP QTS or QuTS hero system to version 5.2.6.3196 or later.
Who is affected by CVE-2025-47208?
CVE-2025-47208 affects users of QNAP QTS and QuTS hero operating systems up to version 5.2.6.3195.
Can CVE-2025-47208 be exploited remotely?
Yes, CVE-2025-47208 can be exploited remotely if the attacker has a valid user account on the affected QNAP systems.