CVE-2025-47212: QTS, QuTS hero
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.2.6.3195 build 20250715 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47212?
CVE-2025-47212 has been classified as a high severity command injection vulnerability.
How do I fix CVE-2025-47212?
To fix CVE-2025-47212, upgrade your QNAP operating system to the latest version beyond 5.2.6.3195.
Which QNAP products are affected by CVE-2025-47212?
CVE-2025-47212 affects QNAP QTS and QNAP QuTS hero operating systems up to version 5.2.6.3195.
What actions can an attacker perform using CVE-2025-47212?
An attacker with an administrator account can exploit CVE-2025-47212 to execute arbitrary commands on the affected system.
Is there a workaround for CVE-2025-47212 before applying the fix?
Currently, there are no recommended workarounds for CVE-2025-47212; applying the patch is essential.