CVE-2025-62849: QTS, QuTS hero
An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62849?
CVE-2025-62849 has been classified as a critical severity due to the potential for remote code execution.
How do I fix CVE-2025-62849?
To fix CVE-2025-62849, update your QNAP QTS or QuTS hero to version 5.2.7.3297 or later.
Which QNAP systems are affected by CVE-2025-62849?
CVE-2025-62849 affects several versions of QNAP QTS and QuTS hero prior to the specified fixed versions.
What type of attack can exploit CVE-2025-62849?
CVE-2025-62849 can be exploited through SQL injection attacks, allowing unauthorized code execution.
Is there a public exploit for CVE-2025-62849?
As of now, details regarding public exploits for CVE-2025-62849 have not been disclosed.