CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-62849: qts 5.2.0.2737 · update build_20240417, 5.2.0.2744 · update build_20240424, 5.2.0.2782 · update build_20240601 (+14…

CVE-2025-62849. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.00966 (percentile 0.6046), scored 2026-10-06.

Affected technology

qts · 5.2.0.2737 · update build_20240417
qnap

qts · 5.2.0.2744 · update build_20240424
qnap

qts · 5.2.0.2782 · update build_20240601
qnap

qts · 5.2.0.2802 · update build_20240620
qnap

qts · 5.2.0.2823 · update build_20240711
qnap

qts · 5.2.0.2851 · update build_20240808
qnap

qts · 5.2.0.2860 · update build_20240817
qnap

qts · 5.2.1.2930 · update build_20241025
qnap

qts · 5.2.2.2950 · update build_20241114
qnap

qts · 5.2.3.3006 · update build_20250108
qnap

qts · 5.2.4.3070 · update build_20250312
qnap

qts · 5.2.4.3079 · update build_20250321
qnap

qts · 5.2.4.3092 · update build_20250403
qnap

qts · 5.2.5.3145 · update build_20250526
qnap

qts · 5.2.6.3195 · update build_20250715
qnap

qts · 5.2.6.3229 · update build_20250818
qnap

qts · 5.2.7.3256 · update build_20250913
qnap

quts hero · h5.2.0.2737 · update build_20240417
qnap

quts hero · h5.2.0.2782 · update build_20240601
qnap

quts hero · h5.2.0.2789 · update build_20240607
qnap

quts hero · h5.2.0.2802 · update build_20240620
qnap

quts hero · h5.2.0.2823 · update build_20240711
qnap

quts hero · h5.2.0.2851 · update build_20240808
qnap

quts hero · h5.2.0.2860 · update build_20240817
qnap

quts hero · h5.2.1.2929 · update build_20241025
qnap

quts hero · h5.2.1.2940 · update build_20241105
qnap

quts hero · h5.2.2.2952 · update build_20241116
qnap

quts hero · h5.2.3.3006 · update build_20250108
qnap

quts hero · h5.2.4.3070 · update build_20250312
qnap

quts hero · h5.2.4.3079 · update build_20250321
qnap

quts hero · h5.2.5.3138 · update build_20250519
qnap

quts hero · h5.2.6.3195 · update build_20250715
qnap

quts hero · h5.2.7.3256 · update build_20250913
qnap

quts hero · h5.3.0.3115 · update build_20250430
qnap

quts hero · h5.3.0.3145 · update build_20250530
qnap

quts hero · h5.3.0.3192 · update build_20250716
qnap

quts hero · h5.3.1.3250 · update build_20250912
qnap

QTS · 5.2.x to before 5.2.7.3297 build 20251024
QNAP Systems Inc.

QuTS hero · h5.2.x to before h5.2.7.3297 build 20251024, h5.3.x to before h5.3.1.3292 build 20251024
QNAP Systems Inc.

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · Passive user interaction

What an attacker can do

The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. Vendor/CNA’s CVSS 4.0 assessment (base score 5.2/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-89
CCR priority
39.4 /100 (P4)
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.00966 · percentile 0.6046 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-62849.html