CVE-2025-33032Medium· 4.9▾ SunlitA path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or s…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later
qts = 5.2.0.2737qts = 5.2.0.2744qts = 5.2.0.2782qts = 5.2.0.2802qts = 5.2.0.2823qts = 5.2.0.2851qts = 5.2.0.2860qts = 5.2.1.2930qts = 5.2.2.2950qts = 5.2.3.3006qts = 5.2.4.3070qts = 5.2.4.3079qts = 5.2.4.3092quts_hero = h5.2.0.2737quts_hero = h5.2.0.2782quts_hero = h5.2.0.2789quts_hero = h5.2.0.2802quts_hero = h5.2.0.2823quts_hero = h5.2.0.2851quts_hero = h5.2.0.2860quts_hero = h5.2.1.2929quts_hero = h5.2.1.2940quts_hero = h5.2.2.2952quts_hero = h5.2.3.3006quts_hero = h5.2.4.3070quts_hero = h5.2.4.3079Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-30270Medium· 6.5A path traversal vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-30271Medium· 6.5A path traversal vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-30272Medium· 6.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-30273High· 8.1An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-30274Medium· 6.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-30268Medium· 6.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions