CVE-2025-9110: QTS, QuTS hero
An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to read application data.
We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later QuTS hero h5.3.1.3250 build 20250912 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9110?
CVE-2025-9110 is rated as a high severity vulnerability due to the potential exposure of sensitive system information.
How do I fix CVE-2025-9110?
To fix CVE-2025-9110, update your QNAP QTS or QuTS hero operating system to the latest version as specified in security advisories.
What versions of QNAP products are affected by CVE-2025-9110?
CVE-2025-9110 affects QNAP QTS versions prior to 5.2.8.3332 and QuTS hero versions prior to h5.2.8.3321 and h5.3.1.3250.
Can CVE-2025-9110 be exploited remotely?
Yes, CVE-2025-9110 can be exploited remotely by attackers to read sensitive application data.
Is there a public proof of concept for CVE-2025-9110?
Currently, there is no public proof of concept for CVE-2025-9110, but its exploitation remains a critical concern.