CVE-2025-52426: QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52426?
CVE-2025-52426 is classified as a denial-of-service vulnerability with severe implications for affected systems.
How do I fix CVE-2025-52426?
To fix CVE-2025-52426, update QNAP QTS or QNAP QuTS hero to versions 5.2.7.3256 or 5.3.1.3250 as applicable.
Which QNAP operating system versions are affected by CVE-2025-52426?
CVE-2025-52426 affects QNAP QTS up to version 5.2.7.3256 and QNAP QuTS hero up to versions 5.2.7.3256 and 5.3.1.3250.
What type of attack can be launched using the CVE-2025-52426 vulnerability?
An attacker exploiting CVE-2025-52426 can launch a denial-of-service (DoS) attack on vulnerable systems.
Who can exploit CVE-2025-52426?
CVE-2025-52426 can be exploited by remote attackers with administrator account access.