CVE-2025-62848: QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62848?
CVE-2025-62848 is classified as a denial-of-service (DoS) vulnerability that can significantly impact system availability.
How do I fix CVE-2025-62848?
To fix CVE-2025-62848, upgrade to QTS version 5.2.7.3297 or later for affected systems.
Which versions of QNAP OS are affected by CVE-2025-62848?
CVE-2025-62848 affects several versions of QNAP QTS and QuTS hero prior to version 5.2.7.3297 and 5.3.1.3292 respectively.
What kind of attack can be launched using CVE-2025-62848?
Attackers can exploit CVE-2025-62848 to launch a denial-of-service (DoS) attack against vulnerable systems.
Is there a workaround for CVE-2025-62848 if I cannot apply the patch?
There are no recommended workarounds for CVE-2025-62848; applying the security update is necessary to mitigate risks.