CVE-2025-52871: License Center
Published Jan 2, 2026
·Updated
An out-of-bounds read vulnerability has been reported to affect License Center. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data.
We have already fixed the vulnerability in the following version: License Center 2.0.36 and later
Affected Software
2 affected components
License Center License Center<2.0.36
QNAP License Center>=2.0.17<2.0.36
Remediation
Information
We have already fixed the vulnerability in the following version:
License Center 2.0.36 and later
Event History
Jan 2, 2026
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52871?
CVE-2025-52871 is considered a high severity vulnerability due to the potential for remote attackers to access secret data.
2
How do I fix CVE-2025-52871?
To fix CVE-2025-52871, upgrade License Center to version 2.0.36 or later.
3
What types of attacks can exploit CVE-2025-52871?
CVE-2025-52871 can be exploited by remote attackers who have gained a user account, allowing them to perform out-of-bounds read operations.
4
What is affected by CVE-2025-52871?
CVE-2025-52871 affects versions of License Center up to 2.0.36.
5
Can CVE-2025-52871 be exploited without a user account?
No, CVE-2025-52871 requires a valid user account for exploitation.