CVE-2025-53592: QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53592?
CVE-2025-53592 is classified as a high severity vulnerability due to its potential to enable denial-of-service attacks.
How do I fix CVE-2025-53592?
To fix CVE-2025-53592, update any affected QNAP systems to the latest versions of QTS or QuTS hero as recommended by QNAP.
Which QNAP systems are affected by CVE-2025-53592?
CVE-2025-53592 affects QNAP QTS up to version 5.2.7.3256 and QuTS hero up to version 5.2.7.3256 and 5.3.1.3250.
What type of attack can be launched using CVE-2025-53592?
An attacker can exploit CVE-2025-53592 to launch a denial-of-service (DoS) attack by dereferencing a NULL pointer.
Is user authentication required to exploit CVE-2025-53592?
Yes, a remote attacker must gain a user account to exploit the CVE-2025-53592 vulnerability.