CVE-2025-30264High· 8.8▾ TwilightA command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixe…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later
qts = 5.2.0.2737qts = 5.2.0.2744qts = 5.2.0.2782qts = 5.2.0.2802qts = 5.2.0.2823qts = 5.2.0.2851qts = 5.2.0.2860qts = 5.2.1.2930qts = 5.2.2.2950qts = 5.2.3.3006qts = 5.2.4.3070qts = 5.2.4.3079qts = 5.2.4.3092quts_hero = h5.2.0.2737quts_hero = h5.2.0.2782quts_hero = h5.2.0.2789quts_hero = h5.2.0.2802quts_hero = h5.2.0.2823quts_hero = h5.2.0.2851quts_hero = h5.2.0.2860quts_hero = h5.2.1.2929quts_hero = h5.2.1.2940quts_hero = h5.2.2.2952quts_hero = h5.2.3.3006quts_hero = h5.2.4.3070quts_hero = h5.2.4.3079Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2018-19949Critical· 9.8If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands
CVE-2025-33032Medium· 4.9A path traversal vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-30272Medium· 6.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-30273High· 8.1An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-30274Medium· 6.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-30268Medium· 6.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions