---
id: CVE-2025-33032
title: >-
  A path traversal vulnerability has been reported to affect several QNAP
  operating system versions
summary: >-
  A path traversal vulnerability has been reported to affect several QNAP
  operating system versions. If a remote attacker gains an administrator
  account, they can then exploit the vulnerability to read the contents of
  unexpected files or s…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: qnap
product: qts
affected:
  - qts = 5.2.0.2737
  - qts = 5.2.0.2744
  - qts = 5.2.0.2782
  - qts = 5.2.0.2802
  - qts = 5.2.0.2823
  - qts = 5.2.0.2851
  - qts = 5.2.0.2860
  - qts = 5.2.1.2930
  - qts = 5.2.2.2950
  - qts = 5.2.3.3006
  - qts = 5.2.4.3070
  - qts = 5.2.4.3079
  - qts = 5.2.4.3092
  - quts_hero = h5.2.0.2737
  - quts_hero = h5.2.0.2782
  - quts_hero = h5.2.0.2789
  - quts_hero = h5.2.0.2802
  - quts_hero = h5.2.0.2823
  - quts_hero = h5.2.0.2851
  - quts_hero = h5.2.0.2860
  - quts_hero = h5.2.1.2929
  - quts_hero = h5.2.1.2940
  - quts_hero = h5.2.2.2952
  - quts_hero = h5.2.3.3006
  - quts_hero = h5.2.4.3070
  - quts_hero = h5.2.4.3079
published: '2025-08-29'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-33032'
references:
  - url: 'https://www.qnap.com/en/security-advisory/qsa-25-21'
    label: security@qnapsecurity.com.tw
tags:
  - nvd
epss: 0.00499
epssPercentile: 0.40226
ingestedAt: '2026-09-26T00:22:39.902Z'
---

## Overview

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.

We have already fixed the vulnerability in the following version:
QTS 5.2.5.3145 build 20250526 and later
QuTS hero h5.2.5.3138 build 20250519 and later

## Affected

- `qts = 5.2.0.2737`
- `qts = 5.2.0.2744`
- `qts = 5.2.0.2782`
- `qts = 5.2.0.2802`
- `qts = 5.2.0.2823`
- `qts = 5.2.0.2851`
- `qts = 5.2.0.2860`
- `qts = 5.2.1.2930`
- `qts = 5.2.2.2950`
- `qts = 5.2.3.3006`
- `qts = 5.2.4.3070`
- `qts = 5.2.4.3079`
- `qts = 5.2.4.3092`
- `quts_hero = h5.2.0.2737`
- `quts_hero = h5.2.0.2782`
- `quts_hero = h5.2.0.2789`
- `quts_hero = h5.2.0.2802`
- `quts_hero = h5.2.0.2823`
- `quts_hero = h5.2.0.2851`
- `quts_hero = h5.2.0.2860`
- `quts_hero = h5.2.1.2929`
- `quts_hero = h5.2.1.2940`
- `quts_hero = h5.2.2.2952`
- `quts_hero = h5.2.3.3006`
- `quts_hero = h5.2.4.3070`
- `quts_hero = h5.2.4.3079`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
