Executive brief
QNAP has released security updates for several of its network-attached storage (NAS) operating systems to address a stability issue. An attacker who has already obtained administrator-level access to the device could trigger a system crash, leading to a denial-of-service. This would disrupt business operations and data availability until the system is recovered.
Technical details
A NULL pointer dereference vulnerability (CWE-476) exists in multiple QNAP operating systems, including QTS and QuTS hero. The flaw is reachable over the network but requires high privileges (administrator account) to exploit. By triggering the dereference, an attacker can cause the affected service or system to crash, resulting in a denial-of-service (DoS) condition. QNAP has released patched firmware versions to address this issue.
Affected products
- QNAP QTS 5.2.9.3492 build 20260507 and later
- QNAP QuTS hero h5.2.9.3499 build 20260514 and later
- QNAP QuTS hero h5.3.4.3500 build 20260520 and later
- QNAP QuTS hero h6.0.0.3459 build 20260409 and later
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory