CVE-2025-66277: QTS, QuTS hero
A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations.
We have already fixed the vulnerability in the following versions: QTS 5.2.8.3350 build 20251216 and later QuTS hero h5.3.2.3354 build 20251225 and later QuTS hero h5.2.8.3350 build 20251216 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66277?
CVE-2025-66277 is classified as a high severity vulnerability that can allow remote attackers to traverse the file system.
How do I fix CVE-2025-66277?
To fix CVE-2025-66277, update to the latest versions of QTS or QuTS hero that address this vulnerability, specifically QTS 5.2.8 or later.
Which QNAP operating system versions are affected by CVE-2025-66277?
CVE-2025-66277 affects multiple versions of QNAP QTS and QuTS hero prior to the fixed releases.
Can CVE-2025-66277 be exploited remotely?
Yes, CVE-2025-66277 can be exploited remotely by attackers to gain unauthorized access to unintended file system locations.
Is there a patch available for CVE-2025-66277?
Yes, a patch is available in the form of updates for QTS 5.2.8 and the corresponding updates for QuTS hero.