CVE-2025-58466: QTS, QuTS hero
A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to denial of service conditions, or modify control flow in unexpected ways.
We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58466?
CVE-2025-58466 is classified as a medium severity vulnerability affecting specific QNAP operating systems.
How do I fix CVE-2025-58466?
To fix CVE-2025-58466, update your QNAP QTS or QuTS hero operating system to the latest patched version released by QNAP.
What are the potential impacts of CVE-2025-58466?
Exploitation of CVE-2025-58466 can lead to denial of service conditions and unexpected modifications in control flow by a remote attacker.
Which versions are affected by CVE-2025-58466?
CVE-2025-58466 affects several versions of QNAP QTS up to 5.2.8.3332 and QuTS hero up to h5.2.8.3321.
Who can exploit CVE-2025-58466?
Only remote attackers with administrator account access can exploit CVE-2025-58466.