A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.0.3192 build 20250716 and later
History

Fri, 02 Jan 2026 15:00:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.0.3192 build 20250716 and later
Title QTS, QuTS hero
First Time appeared Qnap Systems Inc.
Qnap Systems Inc. qts
Qnap Systems Inc. quts Hero
Weaknesses CWE-120
CPEs cpe:2.3:a:qnap_systems_inc.:qts:*:*:*:*:*:*:*:*
cpe:2.3:a:qnap_systems_inc.:quts_hero:*:*:*:*:*:*:*:*
Vendors & Products Qnap Systems Inc.
Qnap Systems Inc. qts
Qnap Systems Inc. quts Hero
References
Metrics cvssV4_0

{'score': 1.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2026-01-02T14:54:14.636Z

Reserved: 2025-06-20T05:55:32.047Z

Link: CVE-2025-52864

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-02T15:16:00.827

Modified: 2026-01-02T16:45:26.640

Link: CVE-2025-52864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.