{"id":"CVE-2025-62852","title":"A buffer overflow vulnerability has been reported to affect several QNAP operating system versions","summary":"A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes.\n\nWe hav…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-121","CWE-787"],"vendor":"qnap","product":"qts","affected":["qts = 5.2.0.2737","qts = 5.2.0.2744","qts = 5.2.0.2782","qts = 5.2.0.2802","qts = 5.2.0.2823","qts = 5.2.0.2851","qts = 5.2.0.2860","qts = 5.2.1.2930","qts = 5.2.2.2950","qts = 5.2.3.3006","qts = 5.2.4.3070","qts = 5.2.4.3079","qts = 5.2.4.3092","qts = 5.2.5.3145","qts = 5.2.6.3195","qts = 5.2.6.3229","qts = 5.2.7.3256","qts = 5.2.7.3297","quts_hero = h5.2.0.2737","quts_hero = h5.2.0.2782","quts_hero = h5.2.0.2789","quts_hero = h5.2.0.2802","quts_hero = h5.2.0.2823","quts_hero = h5.2.0.2851","quts_hero = h5.2.0.2860","quts_hero = h5.2.1.2929","quts_hero = h5.2.1.2940","quts_hero = h5.2.2.2952","quts_hero = h5.2.3.3006","quts_hero = h5.2.4.3070","quts_hero = h5.2.4.3079","quts_hero = h5.2.5.3138","quts_hero = h5.2.6.3195","quts_hero = h5.2.7.3256","quts_hero = h5.2.7.3297","quts_hero = h5.3.0.3115","quts_hero = h5.3.0.3145","quts_hero = h5.3.0.3192"],"published":"2026-01-02","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-62852","references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-25-51","label":"security@qnapsecurity.com.tw"}],"tags":["nvd"],"epss":0.00362,"epssPercentile":0.27564,"ingestedAt":"2026-09-30T23:29:32.521Z","slug":"CVE-2025-62852","body":"## Overview\n\nA buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes.\n\nWe have already fixed the vulnerability in the following version:\nQTS 5.2.8.3332 build 20251128 and later\n\n## Affected\n\n- `qts = 5.2.0.2737`\n- `qts = 5.2.0.2744`\n- `qts = 5.2.0.2782`\n- `qts = 5.2.0.2802`\n- `qts = 5.2.0.2823`\n- `qts = 5.2.0.2851`\n- `qts = 5.2.0.2860`\n- `qts = 5.2.1.2930`\n- `qts = 5.2.2.2950`\n- `qts = 5.2.3.3006`\n- `qts = 5.2.4.3070`\n- `qts = 5.2.4.3079`\n- `qts = 5.2.4.3092`\n- `qts = 5.2.5.3145`\n- `qts = 5.2.6.3195`\n- `qts = 5.2.6.3229`\n- `qts = 5.2.7.3256`\n- `qts = 5.2.7.3297`\n- `quts_hero = h5.2.0.2737`\n- `quts_hero = h5.2.0.2782`\n- `quts_hero = h5.2.0.2789`\n- `quts_hero = h5.2.0.2802`\n- `quts_hero = h5.2.0.2823`\n- `quts_hero = h5.2.0.2851`\n- `quts_hero = h5.2.0.2860`\n- `quts_hero = h5.2.1.2929`\n- `quts_hero = h5.2.1.2940`\n- `quts_hero = h5.2.2.2952`\n- `quts_hero = h5.2.3.3006`\n- `quts_hero = h5.2.4.3070`\n- `quts_hero = h5.2.4.3079`\n- `quts_hero = h5.2.5.3138`\n- `quts_hero = h5.2.6.3195`\n- `quts_hero = h5.2.7.3256`\n- `quts_hero = h5.2.7.3297`\n- `quts_hero = h5.3.0.3115`\n- `quts_hero = h5.3.0.3145`\n- `quts_hero = h5.3.0.3192`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}