CVE-2025-62852: QTS, QuTS hero
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following version: QTS 5.2.8.3332 build 20251128 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62852?
CVE-2025-62852 has been classified as a high-severity vulnerability due to the potential for remote exploitation.
How do I fix CVE-2025-62852?
To fix CVE-2025-62852, update your QNAP QTS to version 5.2.8.3333 or later.
What types of systems are affected by CVE-2025-62852?
CVE-2025-62852 affects several versions of the QNAP QTS operating system prior to 5.2.8.3333.
What is the potential impact of exploiting CVE-2025-62852?
Exploitation of CVE-2025-62852 could allow a remote attacker with administrator access to modify memory or crash system processes.
Has CVE-2025-62852 been publicly disclosed?
Yes, CVE-2025-62852 has been publicly disclosed along with available mitigations and patches.