Junglewise Threat Intelligence

CVE-2025-62850: QNAP QuTS hero NULL pointer dereference causing DoS

CVE-2025-62850 · Severity: info · CVSS 5.1 · Published 2026-06-10

Technologies: QNAP Systems, Inc. QuTS hero. Vendors: QNAP Systems, Inc..

Executive brief

A vulnerability in QNAP's QuTS hero operating system, used in high-performance storage devices, could allow an attacker with administrative access to crash the system. By triggering a specific software error, the attacker can cause a denial-of-service, making the storage and its data temporarily unavailable to the organization. This requires the attacker to already possess high-level administrative credentials.

Technical details

A NULL pointer dereference (CWE-476) exists in several versions of QNAP's QuTS hero operating system. The vulnerability is reachable over the network but requires high privileges (administrative account). An attacker with these credentials can exploit the flaw to cause a system crash or service instability, resulting in a denial-of-service (DoS) condition. QNAP has released patches for the QuTS hero h5.2, h5.3, and h6.0 branches to address this issue.

Affected products

  • QNAP Systems, Inc. QuTS hero h5.2.9.3410 build 20260214, h5.3.4.3500 build 20260520, h6.0.0.3459 build 20260409

Timeline

  • 2026-06-10: advisory: Initial advisory published by QNAP and NVD
  • 2026-02-14: patched: Fix released for QuTS hero h5.2.9.3410
  • 2026-05-20: patched: Fix released for QuTS hero h5.3.4.3500
  • 2026-04-09: patched: Fix released for QuTS hero h6.0.0.3459

References

Related threats