CVE-2025-52872: QTS, QuTS hero
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.0.3192 build 20250716 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52872?
CVE-2025-52872 is classified as a high severity buffer overflow vulnerability.
How do I fix CVE-2025-52872?
To remediate CVE-2025-52872, upgrade your QNAP QTS or QuTS hero to the latest patched version.
Which versions of QNAP operating systems are affected by CVE-2025-52872?
CVE-2025-52872 affects QNAP QTS versions up to 5.2.7.3256 and QuTS hero versions up to 5.2.7.3256 and 5.3.0.3192.
Who can exploit CVE-2025-52872?
A remote attacker with a user account can exploit CVE-2025-52872 to modify memory or crash processes.
What types of attacks can CVE-2025-52872 lead to?
CVE-2025-52872 can lead to unauthorized memory modifications and potential denial of service due to process crashes.