Junglewise Threat Intelligence

CVE-2025-66274: QNAP QTS and QuTS hero NULL pointer dereference

CVE-2025-66274 · Severity: medium · CVSS 4.9 · Published 2026-02-11

Technologies: QNAP QTS. Vendors: QNAP.

Executive brief

A vulnerability in QNAP's network-attached storage (NAS) operating systems could allow an attacker with administrative access to crash the system. By triggering a specific software error, the attacker can cause a denial-of-service, making the storage device and its data temporarily unavailable to the business. This issue affects several versions of the QTS and QuTS hero operating systems.

Technical details

A NULL pointer dereference vulnerability (CWE-476) exists in several QNAP operating system versions, including QTS and QuTS hero. The flaw is reachable over the network but requires high privileges, specifically an administrator account. By exploiting this vulnerability, an authenticated attacker can cause a system crash or process termination, resulting in a denial-of-service (DoS) condition. QNAP has released security updates to address this issue across the affected product lines.

Affected products

  • QNAP QTS 5.2.9.3410 build 20260214 and later
  • QNAP QuTS hero h5.2.9.3410 build 20260214 and later; h5.3.2.3354 build 20251225 and later; h6.0.0.3397 build 20260206 and later

Timeline

  • 2026-02-11: advisory: Initial NVD publication date
  • 2026-02-12: advisory: QNAP security advisory QSA-26-08 published
  • 2025-12-25: patched: Fix released for QuTS hero h5.3.x

References

Related threats