CVE-2025-62848: QNAP QTS

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later

Affected products

  • QNAP QTS: version 5.2.0.2737 only; version 5.2.0.2744 only; version 5.2.0.2782 only; version 5.2.0.2802 only; version 5.2.0.2823 only; version 5.2.0.2851 only; …
  • QNAP Quts Hero: version h5.2.0.2737 only; version h5.2.0.2782 only; version h5.2.0.2789 only; version h5.2.0.2802 only; version h5.2.0.2823 only; version h5.2.0.2851 only; …

Published 2025-12-16. Last modified 2026-10-07.