CVE-2025-53591: QTS, QuTS hero
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53591?
CVE-2025-53591 is categorized as a high severity vulnerability due to its potential for remote exploitation by an attacker with an administrator account.
How do I fix CVE-2025-53591?
To fix CVE-2025-53591, update your QNAP QTS or QuTS hero to the latest versions released by QNAP.
What are the affected software versions for CVE-2025-53591?
CVE-2025-53591 affects QNAP QTS versions up to 5.2.7.3256 and QuTS hero versions up to h5.2.7.3256 and h5.3.1.3250.
What kind of attack can exploit CVE-2025-53591?
An attacker can exploit CVE-2025-53591 to gain unauthorized access, potentially allowing them to retrieve sensitive information or manipulate memory.
Is there a patch available for CVE-2025-53591?
Yes, QNAP has released a patch to address CVE-2025-53591, which can be applied by updating your affected software.