CVE-2025-66274: QTS, QuTS hero
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.2.3354 build 20251225 and later QuTS hero h6.0.0.3397 build 20260206 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66274?
CVE-2025-66274 is classified as a high severity vulnerability due to its potential to cause denial-of-service (DoS) attacks.
How do I fix CVE-2025-66274?
To fix CVE-2025-66274, update your QNAP QuTS hero operating system to the latest version provided by QNAP.
Which QNAP QuTS hero versions are affected by CVE-2025-66274?
CVE-2025-66274 affects multiple versions of QNAP QuTS hero including versions up to h5.3.2.3354.
Can CVE-2025-66274 be exploited remotely?
Yes, CVE-2025-66274 can be exploited remotely if an attacker gains administrative access.
What is the impact of CVE-2025-66274?
The impact of CVE-2025-66274 can lead to a denial-of-service condition, potentially disrupting the affected system's operations.