Low severityNVD Advisory· Published Jun 10, 2026· Updated Jun 12, 2026
CVE-2025-59382
CVE-2025-59382
Description
QTS, QuTS hero, QuTScloud are not affected.
We have already fixed the vulnerability in the following version:
Patches
Vulnerability mechanics
References
1News mentions
3- QNAP Patches Multiple Injection Vulnerabilities Leads to Arbitrary Command ExecutionCyber Security News · Jun 22, 2026
- QNAP QTS: Critical Command Injection and XSS Flaws Disclosed in BatchVypr Intelligence · Jun 10, 2026
- QNAP QuTS hero: 12 Vulnerabilities Disclosed, Including Command Injection and XSSVypr Intelligence · Jun 10, 2026