CVE-2025-48721: QTS, QuTS hero
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following version: QTS 5.2.8.3332 build 20251128 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48721?
CVE-2025-48721 has been classified as a high severity buffer overflow vulnerability.
How do I fix CVE-2025-48721?
To fix CVE-2025-48721, update your QNAP operating system to version 5.2.8.3333 or later.
Which QNAP products are affected by CVE-2025-48721?
CVE-2025-48721 affects several versions of QNAP QTS and QuTS hero up to version 5.2.8.3332.
Can CVE-2025-48721 be exploited remotely?
Yes, CVE-2025-48721 can be exploited remotely if an attacker gains access to an administrator account.
What can an attacker achieve by exploiting CVE-2025-48721?
An attacker exploiting CVE-2025-48721 can modify memory or crash processes on the affected systems.