{"id":"CVE-2025-30270","title":"A path traversal vulnerability has been reported to affect several QNAP operating system versions","summary":"A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-22"],"vendor":"qnap","product":"qts","affected":["qts = 5.2.0.2737","qts = 5.2.0.2744","qts = 5.2.0.2782","qts = 5.2.0.2802","qts = 5.2.0.2823","qts = 5.2.0.2851","qts = 5.2.0.2860","qts = 5.2.1.2930","qts = 5.2.2.2950","qts = 5.2.3.3006","qts = 5.2.4.3070","qts = 5.2.4.3079","qts = 5.2.4.3092","quts_hero = h5.2.0.2737","quts_hero = h5.2.0.2782","quts_hero = h5.2.0.2789","quts_hero = h5.2.0.2802","quts_hero = h5.2.0.2823","quts_hero = h5.2.0.2851","quts_hero = h5.2.0.2860","quts_hero = h5.2.1.2929","quts_hero = h5.2.1.2940","quts_hero = h5.2.2.2952","quts_hero = h5.2.3.3006","quts_hero = h5.2.4.3070","quts_hero = h5.2.4.3079"],"published":"2025-08-29","updated":"2026-09-26","sourceUpdated":"2026-09-26T00:10:00.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-30270","references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-25-21","label":"security@qnapsecurity.com.tw"}],"tags":["nvd"],"epss":0.00488,"epssPercentile":0.3939,"ingestedAt":"2026-09-26T00:22:39.900Z","slug":"CVE-2025-30270","body":"## Overview\n\nA path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.5.3145 build 20250526 and later\nQuTS hero h5.2.5.3138 build 20250519 and later\n\n## Affected\n\n- `qts = 5.2.0.2737`\n- `qts = 5.2.0.2744`\n- `qts = 5.2.0.2782`\n- `qts = 5.2.0.2802`\n- `qts = 5.2.0.2823`\n- `qts = 5.2.0.2851`\n- `qts = 5.2.0.2860`\n- `qts = 5.2.1.2930`\n- `qts = 5.2.2.2950`\n- `qts = 5.2.3.3006`\n- `qts = 5.2.4.3070`\n- `qts = 5.2.4.3079`\n- `qts = 5.2.4.3092`\n- `quts_hero = h5.2.0.2737`\n- `quts_hero = h5.2.0.2782`\n- `quts_hero = h5.2.0.2789`\n- `quts_hero = h5.2.0.2802`\n- `quts_hero = h5.2.0.2823`\n- `quts_hero = h5.2.0.2851`\n- `quts_hero = h5.2.0.2860`\n- `quts_hero = h5.2.1.2929`\n- `quts_hero = h5.2.1.2940`\n- `quts_hero = h5.2.2.2952`\n- `quts_hero = h5.2.3.3006`\n- `quts_hero = h5.2.4.3070`\n- `quts_hero = h5.2.4.3079`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}