CVE-2025-52861: QNAP Systems Inc VioStor

High severity, CVSS 7.0. EPSS: 0.6% chance of exploitation in the next 30 days.

A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621 and later

Affected products

  • QNAP Systems Inc VioStor: from 5.1.0, before 5.1.6 build 20250621 (fixed in 5.1.6 build 20250621)

Published 2025-08-29. Last modified 2026-06-17.