← CVE Tracker
8.8HIGH

CVE-2025-30264 — A command injection vulnerability has been reported to affect several QNAP operating system versions.

Qnap · Qts · Published 29 Aug 2025 · Modified 26 Sept 2026

Description

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

References

What to do
  1. Check whether Qts is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-30264