CVE-2025-54166: QTS, QuTS hero
An out-of-bounds read vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54166?
CVE-2025-54166 is classified as a high-severity vulnerability due to its potential for remote exploitation by an attacker with administrator access.
How do I fix CVE-2025-54166?
To fix CVE-2025-54166, users should upgrade to the latest versions of QNAP QTS above 5.2.7.3256 or QuTS hero above 5.3.1.3250.
What types of systems are affected by CVE-2025-54166?
CVE-2025-54166 affects several versions of QNAP QTS and QuTS hero operating systems.
What can an attacker do by exploiting CVE-2025-54166?
An attacker who exploits CVE-2025-54166 can perform out-of-bounds read operations to access sensitive data.
Is there a workaround for CVE-2025-54166?
There is no official workaround for CVE-2025-54166; the recommended action is to apply the latest software updates.