CVE-2025-53589: QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53589?
CVE-2025-53589 is a high severity vulnerability that allows a remote attacker to exploit a NULL pointer dereference and potentially launch a denial-of-service attack.
How do I fix CVE-2025-53589?
To mitigate CVE-2025-53589, ensure that your QNAP system is updated to the latest version of QTS or QuTS hero that contains the security fix.
Which QNAP operating system versions are affected by CVE-2025-53589?
CVE-2025-53589 affects QNAP QTS versions up to 5.2.7.3256 and QuTS hero versions up to 5.2.7.3256 and 5.3.1.3250.
Can CVE-2025-53589 be exploited remotely?
Yes, CVE-2025-53589 can be exploited remotely if the attacker has gained administrator access to the affected QNAP systems.
What type of attack can be launched using CVE-2025-53589?
An attacker exploiting CVE-2025-53589 can launch a denial-of-service (DoS) attack against the affected QNAP devices.