Executive brief
A security vulnerability has been identified in QNAP storage and operating system products. This flaw involves the manipulation of web parameters that were intended to be unchangeable, which could allow an attacker to modify certain system settings or data. While the impact is limited, it could potentially affect the integrity of the device's configuration if a user interacts with a malicious link.
Technical details
The vulnerability is classified as CWE-472 (External Control of Assumed-Immutable Web Parameter). It exists in QNAP's QTS, QuTS hero, and QuTScloud operating systems. An attacker can exploit this by tricking a user into performing an action (UI:A) that sends a crafted network request to the device, allowing the attacker to modify parameters that the application assumes are immutable. This results in a loss of integrity (VI:L) but does not directly lead to data exposure or service denial. QNAP has indicated that fixes are available in recent versions.
Affected products
- QNAP QTS
- QNAP QuTS hero
- QNAP QuTScloud
Timeline
- 2026-06-10: advisory: QNAP published security advisory QSA-26-10
- 2026-06-10: disclosed: CVE-2025-59382 published to the NVD dataset