CVE-2025-62847: QTS, QuTS hero
An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability CVE-2025-62847?
CVE-2025-62847 is an improper neutralization of argument delimiters in a command vulnerability affecting several QNAP operating system versions.
What are the potential consequences of CVE-2025-62847?
Remote attackers can exploit CVE-2025-62847 to alter execution logic on affected systems.
How do I remediate CVE-2025-62847?
To fix CVE-2025-62847, update your QNAP devices to the latest firmware versions that have addressed this vulnerability.
Which QNAP products are affected by CVE-2025-62847?
CVE-2025-62847 affects QNAP QTS up to version 5.2.7.3297 and QNAP QuTS hero up to versions h5.2.7.3297 and h5.3.1.3292.
Is there a patch available for CVE-2025-62847?
Yes, QNAP has released patches addressing CVE-2025-62847 for the affected operating system versions.