Junglewise Threat Intelligence

CVE-2025-66276: QNAP QTS NFS service access control bypass

CVE-2025-66276 · Severity: info · CVSS 9.2 · Published 2026-06-10

Vendors: QNAP Systems, Inc..

Executive brief

A vulnerability exists in legacy QNAP QTS operating systems when the Network File System (NFS) service is enabled. This flaw allows remote attackers to bypass security restrictions and potentially gain unauthorized access to files stored on the NAS device. This could lead to the theft or modification of sensitive company data and disruption of storage operations.

Technical details

A vulnerability in legacy QNAP QTS (specifically version 4.3.x) involves improper access control or misconfiguration within the NFS (Network File System) service. The flaw allows a remote attacker to bypass intended folder permissions and perform unauthorized actions on the file system. The vendor indicates that the issue stems from weak default NFS settings, such as the use of wildcards in host access lists and improper squash options. Attackers can exploit this over the network without authentication if the NFS service is exposed. QNAP has released QTS 5.2.7.3256 build 20250913 to address the issue and recommends manual hardening of NFS host access and squash settings.

Affected products

  • QNAP Systems, Inc. QTS 4.3.x

Timeline

  • 2026-01-17: advisory: Initial advisory QSA-25-56 published by QNAP
  • 2026-06-10: disclosed: CVE record published to NVD

References