CVE-2025-54164: QTS, QuTS hero
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54164?
The severity of CVE-2025-54164 is classified as high due to its potential to allow remote attackers to exploit the vulnerability after gaining administrator access.
How do I fix CVE-2025-54164?
To fix CVE-2025-54164, update your QNAP QTS or QuTS hero software to versions 5.2.7.3256 or later.
What types of systems are affected by CVE-2025-54164?
CVE-2025-54164 affects QNAP QTS versions up to 5.2.7.3256 and QuTS hero versions up to 5.2.7.3256 and 5.3.1.3250.
What could happen if CVE-2025-54164 is exploited?
If exploited, CVE-2025-54164 could allow remote attackers to gain access to sensitive data on affected systems.
Is there a known fix for CVE-2025-54164?
Yes, a known fix for CVE-2025-54164 is available through software updates for the affected QNAP operating system versions.