CVE-2025-57705: QTS, QuTS hero
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57705?
The severity of CVE-2025-57705 is critical due to its potential to allow remote attackers to exhaust system resources.
How do I fix CVE-2025-57705?
To fix CVE-2025-57705, update the affected QNAP QTS or QuTS hero software to the latest version available.
What versions of QNAP software are affected by CVE-2025-57705?
CVE-2025-57705 affects QNAP QTS versions up to 5.2.7.3256 and QuTS hero versions up to 5.2.7.3256 and 5.3.1.3250.
Can CVE-2025-57705 be exploited without an administrator account?
No, CVE-2025-57705 requires a remote attacker to have an administrator account to exploit the vulnerability.
What are the risks associated with CVE-2025-57705?
The risks include the potential for a remote attacker to exhaust resources, leading to system instability and denial of service.