CVE-2025-62852: QNAP QTS

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: QTS 5.2.8.3332 build 20251128 and later

Affected products

  • QNAP QTS: version 5.2.0.2737 only; version 5.2.0.2744 only; version 5.2.0.2782 only; version 5.2.0.2802 only; version 5.2.0.2823 only; version 5.2.0.2851 only; …
  • QNAP Quts Hero: version h5.2.0.2737 only; version h5.2.0.2782 only; version h5.2.0.2789 only; version h5.2.0.2802 only; version h5.2.0.2823 only; version h5.2.0.2851 only; …

Published 2026-01-02. Last modified 2026-10-07.