{"id":"CVE-2025-62847","title":"An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions","summary":"An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic.\n\nWe have a…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-88"],"vendor":"qnap","product":"qts","affected":["qts = 5.2.0.2737","qts = 5.2.0.2744","qts = 5.2.0.2782","qts = 5.2.0.2802","qts = 5.2.0.2823","qts = 5.2.0.2851","qts = 5.2.0.2860","qts = 5.2.1.2930","qts = 5.2.2.2950","qts = 5.2.3.3006","qts = 5.2.4.3070","qts = 5.2.4.3079","qts = 5.2.4.3092","qts = 5.2.5.3145","qts = 5.2.6.3195","qts = 5.2.6.3229","qts = 5.2.7.3256","quts_hero = h5.2.0.2737","quts_hero = h5.2.0.2782","quts_hero = h5.2.0.2789","quts_hero = h5.2.0.2802","quts_hero = h5.2.0.2823","quts_hero = h5.2.0.2851","quts_hero = h5.2.0.2860","quts_hero = h5.2.1.2929","quts_hero = h5.2.1.2940","quts_hero = h5.2.2.2952","quts_hero = h5.2.3.3006","quts_hero = h5.2.4.3070","quts_hero = h5.2.4.3079","quts_hero = h5.2.5.3138","quts_hero = h5.2.6.3195","quts_hero = h5.2.7.3256","quts_hero = h5.3.0.3115","quts_hero = h5.3.0.3145","quts_hero = h5.3.0.3192","quts_hero = h5.3.1.3250"],"published":"2025-12-16","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:10:00.160","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-62847","references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-25-45","label":"security@qnapsecurity.com.tw"}],"tags":["nvd"],"epss":0.00818,"epssPercentile":0.55745,"ingestedAt":"2026-10-07T20:46:46.947Z","slug":"CVE-2025-62847","body":"## Overview\n\nAn improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.2.7.3297 build 20251024 and later\nQuTS hero h5.2.7.3297 build 20251024 and later\nQuTS hero h5.3.1.3292 build 20251024 and later\n\n## Affected\n\n- `qts = 5.2.0.2737`\n- `qts = 5.2.0.2744`\n- `qts = 5.2.0.2782`\n- `qts = 5.2.0.2802`\n- `qts = 5.2.0.2823`\n- `qts = 5.2.0.2851`\n- `qts = 5.2.0.2860`\n- `qts = 5.2.1.2930`\n- `qts = 5.2.2.2950`\n- `qts = 5.2.3.3006`\n- `qts = 5.2.4.3070`\n- `qts = 5.2.4.3079`\n- `qts = 5.2.4.3092`\n- `qts = 5.2.5.3145`\n- `qts = 5.2.6.3195`\n- `qts = 5.2.6.3229`\n- `qts = 5.2.7.3256`\n- `quts_hero = h5.2.0.2737`\n- `quts_hero = h5.2.0.2782`\n- `quts_hero = h5.2.0.2789`\n- `quts_hero = h5.2.0.2802`\n- `quts_hero = h5.2.0.2823`\n- `quts_hero = h5.2.0.2851`\n- `quts_hero = h5.2.0.2860`\n- `quts_hero = h5.2.1.2929`\n- `quts_hero = h5.2.1.2940`\n- `quts_hero = h5.2.2.2952`\n- `quts_hero = h5.2.3.3006`\n- `quts_hero = h5.2.4.3070`\n- `quts_hero = h5.2.4.3079`\n- `quts_hero = h5.2.5.3138`\n- `quts_hero = h5.2.6.3195`\n- `quts_hero = h5.2.7.3256`\n- `quts_hero = h5.3.0.3115`\n- `quts_hero = h5.3.0.3145`\n- `quts_hero = h5.3.0.3192`\n- `quts_hero = h5.3.1.3250`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}