Junglewise Threat Intelligence

CVE-2025-62858: QNAP QTS and QuTS hero buffer overflow

CVE-2025-62858 · Severity: info · CVSS 5.1 · Published 2026-06-09

Technologies: QNAP Systems, Inc. QuTS hero. Vendors: QNAP Systems, Inc..

Executive brief

A security vulnerability has been identified in QNAP network-attached storage (NAS) operating systems. If an attacker manages to obtain administrator credentials, they can trigger a system error that allows them to modify system memory or cause the device to crash. This could lead to service interruptions or unauthorized changes to the storage environment.

Technical details

A stack-based buffer overflow (CWE-121) exists in QNAP QTS and QuTS hero operating systems. The vulnerability is reachable over the network but requires high privileges (administrator account) to exploit. Successful exploitation allows an authenticated attacker to modify memory or cause a denial-of-service (DoS) by crashing system processes. QNAP has released patches for QTS 5.2.9, QuTS hero h5.2.9, h5.3.4, and h6.0.0 to address this issue.

Affected products

  • QNAP Systems, Inc. QTS 5.2.x versions prior to 5.2.9.3410 build 20260214
  • QNAP Systems, Inc. QuTS hero h5.2.x prior to h5.2.9.3410 build 20260214; h5.3.x prior to h5.3.4.3500 build 20260520; h6.0.x prior to h6.0.0.3397 build 20260206

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats