{"id":"CVE-2025-30264","title":"A command injection vulnerability has been reported to affect several QNAP operating system versions","summary":"A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands.\n\nWe have already fixe…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-77","CWE-78"],"vendor":"qnap","product":"qts","affected":["qts = 5.2.0.2737","qts = 5.2.0.2744","qts = 5.2.0.2782","qts = 5.2.0.2802","qts = 5.2.0.2823","qts = 5.2.0.2851","qts = 5.2.0.2860","qts = 5.2.1.2930","qts = 5.2.2.2950","qts = 5.2.3.3006","qts = 5.2.4.3070","qts = 5.2.4.3079","qts = 5.2.4.3092","quts_hero = h5.2.0.2737","quts_hero = h5.2.0.2782","quts_hero = h5.2.0.2789","quts_hero = h5.2.0.2802","quts_hero = h5.2.0.2823","quts_hero = h5.2.0.2851","quts_hero = h5.2.0.2860","quts_hero = h5.2.1.2929","quts_hero = h5.2.1.2940","quts_hero = h5.2.2.2952","quts_hero = h5.2.3.3006","quts_hero = h5.2.4.3070","quts_hero = h5.2.4.3079"],"published":"2025-08-29","updated":"2026-09-26","sourceUpdated":"2026-09-26T00:10:00.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-30264","references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-25-21","label":"security@qnapsecurity.com.tw"}],"tags":["nvd"],"epss":0.00908,"epssPercentile":0.58259,"ingestedAt":"2026-09-26T00:22:39.899Z","slug":"CVE-2025-30264","body":"## Overview\n\nA command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.5.3145 build 20250526 and later\nQuTS hero h5.2.5.3138 build 20250519 and later\n\n## Affected\n\n- `qts = 5.2.0.2737`\n- `qts = 5.2.0.2744`\n- `qts = 5.2.0.2782`\n- `qts = 5.2.0.2802`\n- `qts = 5.2.0.2823`\n- `qts = 5.2.0.2851`\n- `qts = 5.2.0.2860`\n- `qts = 5.2.1.2930`\n- `qts = 5.2.2.2950`\n- `qts = 5.2.3.3006`\n- `qts = 5.2.4.3070`\n- `qts = 5.2.4.3079`\n- `qts = 5.2.4.3092`\n- `quts_hero = h5.2.0.2737`\n- `quts_hero = h5.2.0.2782`\n- `quts_hero = h5.2.0.2789`\n- `quts_hero = h5.2.0.2802`\n- `quts_hero = h5.2.0.2823`\n- `quts_hero = h5.2.0.2851`\n- `quts_hero = h5.2.0.2860`\n- `quts_hero = h5.2.1.2929`\n- `quts_hero = h5.2.1.2940`\n- `quts_hero = h5.2.2.2952`\n- `quts_hero = h5.2.3.3006`\n- `quts_hero = h5.2.4.3070`\n- `quts_hero = h5.2.4.3079`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}