---
id: CVE-2025-30267
title: >-
  A NULL pointer dereference vulnerability has been reported to affect several
  QNAP operating system versions
summary: >-
  A NULL pointer dereference vulnerability has been reported to affect several
  QNAP operating system versions. If a remote attacker gains a user account,
  they can then exploit the vulnerability to launch a denial-of-service (DoS)
  attack.


  …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: qnap
product: qts
affected:
  - qts = 5.2.0.2737
  - qts = 5.2.0.2744
  - qts = 5.2.0.2782
  - qts = 5.2.0.2802
  - qts = 5.2.0.2823
  - qts = 5.2.0.2851
  - qts = 5.2.0.2860
  - qts = 5.2.1.2930
  - qts = 5.2.2.2950
  - qts = 5.2.3.3006
  - qts = 5.2.4.3070
  - qts = 5.2.4.3079
  - qts = 5.2.4.3092
  - quts_hero = h5.2.0.2737
  - quts_hero = h5.2.0.2782
  - quts_hero = h5.2.0.2789
  - quts_hero = h5.2.0.2802
  - quts_hero = h5.2.0.2823
  - quts_hero = h5.2.0.2851
  - quts_hero = h5.2.0.2860
  - quts_hero = h5.2.1.2929
  - quts_hero = h5.2.1.2940
  - quts_hero = h5.2.2.2952
  - quts_hero = h5.2.3.3006
  - quts_hero = h5.2.4.3070
  - quts_hero = h5.2.4.3079
published: '2025-08-29'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-30267'
references:
  - url: 'https://www.qnap.com/en/security-advisory/qsa-25-21'
    label: security@qnapsecurity.com.tw
tags:
  - nvd
epss: 0.00373
epssPercentile: 0.28512
ingestedAt: '2026-09-26T00:22:39.899Z'
---

## Overview

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.

We have already fixed the vulnerability in the following versions:
QTS 5.2.5.3145 build 20250526 and later
QuTS hero h5.2.5.3138 build 20250519 and later

## Affected

- `qts = 5.2.0.2737`
- `qts = 5.2.0.2744`
- `qts = 5.2.0.2782`
- `qts = 5.2.0.2802`
- `qts = 5.2.0.2823`
- `qts = 5.2.0.2851`
- `qts = 5.2.0.2860`
- `qts = 5.2.1.2930`
- `qts = 5.2.2.2950`
- `qts = 5.2.3.3006`
- `qts = 5.2.4.3070`
- `qts = 5.2.4.3079`
- `qts = 5.2.4.3092`
- `quts_hero = h5.2.0.2737`
- `quts_hero = h5.2.0.2782`
- `quts_hero = h5.2.0.2789`
- `quts_hero = h5.2.0.2802`
- `quts_hero = h5.2.0.2823`
- `quts_hero = h5.2.0.2851`
- `quts_hero = h5.2.0.2860`
- `quts_hero = h5.2.1.2929`
- `quts_hero = h5.2.1.2940`
- `quts_hero = h5.2.2.2952`
- `quts_hero = h5.2.3.3006`
- `quts_hero = h5.2.4.3070`
- `quts_hero = h5.2.4.3079`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
