An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3297 build 20251024 and later
QuTS hero h5.2.7.3297 build 20251024 and later
QuTS hero h5.3.1.3292 build 20251024 and later
References
| Link | Resource |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-45 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2025-12-16 03:15
Updated : 2025-12-17 14:00
NVD link : CVE-2025-59385
Mitre link : CVE-2025-59385
CVE.ORG link : CVE-2025-59385
JSON object : View
Products Affected
qnap
- quts_hero
- qts
CWE
CWE-290
Authentication Bypass by Spoofing
