CVE-2025-62849Critical· 9.8▾ MidnightAn SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.0%
An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands.
We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later
qts = 5.2.0.2737qts = 5.2.0.2744qts = 5.2.0.2782qts = 5.2.0.2802qts = 5.2.0.2823qts = 5.2.0.2851qts = 5.2.0.2860qts = 5.2.1.2930qts = 5.2.2.2950qts = 5.2.3.3006qts = 5.2.4.3070qts = 5.2.4.3079qts = 5.2.4.3092qts = 5.2.5.3145qts = 5.2.6.3195qts = 5.2.6.3229qts = 5.2.7.3256quts_hero = h5.2.0.2737quts_hero = h5.2.0.2782quts_hero = h5.2.0.2789quts_hero = h5.2.0.2802quts_hero = h5.2.0.2823quts_hero = h5.2.0.2851quts_hero = h5.2.0.2860quts_hero = h5.2.1.2929quts_hero = h5.2.1.2940quts_hero = h5.2.2.2952quts_hero = h5.2.3.3006quts_hero = h5.2.4.3070quts_hero = h5.2.4.3079quts_hero = h5.2.5.3138quts_hero = h5.2.6.3195quts_hero = h5.2.7.3256quts_hero = h5.3.0.3115quts_hero = h5.3.0.3145quts_hero = h5.3.0.3192quts_hero = h5.3.1.3250Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59385Critical· 9.8An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-62847High· 7.5An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-62848High· 7.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-62852Medium· 6.5A buffer overflow vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-48721Medium· 6.5A buffer overflow vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-33032Medium· 4.9A path traversal vulnerability has been reported to affect several QNAP operating system versions