CVE-2025-59385: QTS, QuTS hero
An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59385?
CVE-2025-59385 is considered a high severity vulnerability due to its potential for remote exploitation leading to unauthorized access.
How do I fix CVE-2025-59385?
To fix CVE-2025-59385, users should update their QNAP QTS or QuTS hero operating systems to the latest version released by QNAP.
What are the affected versions for CVE-2025-59385?
CVE-2025-59385 affects QNAP QTS versions up to 5.2.7.3297 and QuTS hero versions up to 5.3.1.3292.
Can CVE-2025-59385 be exploited remotely?
Yes, CVE-2025-59385 can be exploited remotely by attackers to bypass authentication and access restricted resources.
Is CVE-2025-59385 a local or remote vulnerability?
CVE-2025-59385 is a remote vulnerability that allows attackers to exploit it from outside the affected systems.