VYPR
Medium severity6.5NVD Advisory· Published Jun 9, 2026· Updated Jun 12, 2026

CVE-2025-62858

CVE-2025-62858

Description

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes.

We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3397 build 20260206 and later

Affected products

52
  • Qnap/Qts22 versions
    cpe:2.3:o:qnap:qts:5.2.0.2737:build_20240417:*:*:*:*:*:*+ 21 more
    • cpe:2.3:o:qnap:qts:5.2.0.2737:build_20240417:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.0.2744:build_20240424:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.0.2782:build_20240601:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.0.2802:build_20240620:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.0.2823:build_20240711:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.0.2851:build_20240808:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.0.2860:build_20240817:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.1.2930:build_20241025:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.2.2950:build_20241114:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.3.3006:build_20250108:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.4.3070:build_20250312:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.4.3079:build_20250321:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.4.3092:build_20250403:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.5.3145:build_20250526:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.6.3195:build_20250715:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.6.3229:build_20250818:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.7.3256:build_20250913:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.7.3297:build_20251024:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.8.3332:build_20251128:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.8.3350:build_20251216:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:5.2.8.3359:build_20251225:*:*:*:*:*:*
    • (no CPE)range: <5.2.9.3410 build 20260214
  • Qnap/Quts Hero30 versions
    cpe:2.3:o:qnap:quts_hero:h5.2.0.2737:build_20240417:*:*:*:*:*:*+ 29 more
    • cpe:2.3:o:qnap:quts_hero:h5.2.0.2737:build_20240417:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.0.2782:build_20240601:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.0.2789:build_20240607:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.0.2802:build_20240620:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.0.2823:build_20240711:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.0.2851:build_20240808:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.0.2860:build_20240817:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.1.2929:build_20241025:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.1.2940:build_20241105:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.2.2952:build_20241116:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.3.3006:build_20250108:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.4.3070:build_20250312:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.4.3079:build_20250321:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.5.3138:build_20250519:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.6.3195:build_20250715:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.7.3256:build_20250913:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.7.3297:build_20251024:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.8.3321:build_20251117:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.8.3350:build_20251216:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.2.8.3359:build_20251225:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.3.0.3115:build_20250430:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.3.0.3145:build_20250530:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.3.0.3192:build_20250716:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.3.1.3250:build_20250912:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.3.1.3292:build_20251024:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.3.2.3354:build_20251225:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h5.3.3.3424:build_20260305:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h6.0.0.3324:build_20251125:*:*:*:*:*:*
    • cpe:2.3:o:qnap:quts_hero:h6.0.0.3382:build_20260122:*:*:*:*:*:*
    • (no CPE)range: <h5.2.9.3410 build 20260214 (for h5.2.x series) / <h5.3.4.3500 build 20260520 (for h5.3.x series) / <h6.0.0.3397 build 20260206 (for h6.0.x series)

Patches

Vulnerability mechanics

References

1

News mentions

4