Command Injection Vulnerability in QNAP Operating Systems
CVE-2025-22481
8.7HIGH
What is CVE-2025-22481?
A command injection vulnerability has been identified in several versions of QNAP operating systems. This flaw could permit remote attackers who have successfully obtained user access to execute arbitrary commands on the affected systems. Affected versions include QTS 5.2.4.3079 and earlier, as well as QuTS hero h5.2.4.3079 and earlier. To mitigate this risk, users are advised to upgrade to the latest versions, which contain necessary security patches.
Affected Version(s)
QTS 5.2.x < 5.2.4.3079 build 20250321
QuTS hero h5.2.x