{"id":"CVE-2025-59385","title":"An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions","summary":"An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-290"],"vendor":"qnap","product":"qts","affected":["qts = 5.2.0.2737","qts = 5.2.0.2744","qts = 5.2.0.2782","qts = 5.2.0.2802","qts = 5.2.0.2823","qts = 5.2.0.2851","qts = 5.2.0.2860","qts = 5.2.1.2930","qts = 5.2.2.2950","qts = 5.2.3.3006","qts = 5.2.4.3070","qts = 5.2.4.3079","qts = 5.2.4.3092","qts = 5.2.5.3145","qts = 5.2.6.3195","qts = 5.2.6.3229","qts = 5.2.7.3256","quts_hero = h5.2.0.2737","quts_hero = h5.2.0.2782","quts_hero = h5.2.0.2789","quts_hero = h5.2.0.2802","quts_hero = h5.2.0.2823","quts_hero = h5.2.0.2851","quts_hero = h5.2.0.2860","quts_hero = h5.2.1.2929","quts_hero = h5.2.1.2940","quts_hero = h5.2.2.2952","quts_hero = h5.2.3.3006","quts_hero = h5.2.4.3070","quts_hero = h5.2.4.3079","quts_hero = h5.2.5.3138","quts_hero = h5.2.6.3195","quts_hero = h5.2.7.3256","quts_hero = h5.3.0.3115","quts_hero = h5.3.0.3145","quts_hero = h5.3.0.3192","quts_hero = h5.3.1.3250"],"published":"2025-12-16","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:10:00.160","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-59385","references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-25-45","label":"security@qnapsecurity.com.tw"}],"tags":["nvd"],"epss":0.00636,"epssPercentile":0.48766,"ingestedAt":"2026-10-07T20:46:46.947Z","slug":"CVE-2025-59385","body":"## Overview\n\nAn authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.7.3297 build 20251024 and later\nQuTS hero h5.2.7.3297 build 20251024 and later\nQuTS hero h5.3.1.3292 build 20251024 and later\n\n## Affected\n\n- `qts = 5.2.0.2737`\n- `qts = 5.2.0.2744`\n- `qts = 5.2.0.2782`\n- `qts = 5.2.0.2802`\n- `qts = 5.2.0.2823`\n- `qts = 5.2.0.2851`\n- `qts = 5.2.0.2860`\n- `qts = 5.2.1.2930`\n- `qts = 5.2.2.2950`\n- `qts = 5.2.3.3006`\n- `qts = 5.2.4.3070`\n- `qts = 5.2.4.3079`\n- `qts = 5.2.4.3092`\n- `qts = 5.2.5.3145`\n- `qts = 5.2.6.3195`\n- `qts = 5.2.6.3229`\n- `qts = 5.2.7.3256`\n- `quts_hero = h5.2.0.2737`\n- `quts_hero = h5.2.0.2782`\n- `quts_hero = h5.2.0.2789`\n- `quts_hero = h5.2.0.2802`\n- `quts_hero = h5.2.0.2823`\n- `quts_hero = h5.2.0.2851`\n- `quts_hero = h5.2.0.2860`\n- `quts_hero = h5.2.1.2929`\n- `quts_hero = h5.2.1.2940`\n- `quts_hero = h5.2.2.2952`\n- `quts_hero = h5.2.3.3006`\n- `quts_hero = h5.2.4.3070`\n- `quts_hero = h5.2.4.3079`\n- `quts_hero = h5.2.5.3138`\n- `quts_hero = h5.2.6.3195`\n- `quts_hero = h5.2.7.3256`\n- `quts_hero = h5.3.0.3115`\n- `quts_hero = h5.3.0.3145`\n- `quts_hero = h5.3.0.3192`\n- `quts_hero = h5.3.1.3250`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}