Command Injection Vulnerability in QNAP Operating Systems
CVE-2025-22481

8.7HIGH

Key Information:

Vendor

QNAP

Vendor
CVE Published:
6 June 2025

What is CVE-2025-22481?

A command injection vulnerability has been identified in several versions of QNAP operating systems. This flaw could permit remote attackers who have successfully obtained user access to execute arbitrary commands on the affected systems. Affected versions include QTS 5.2.4.3079 and earlier, as well as QuTS hero h5.2.4.3079 and earlier. To mitigate this risk, users are advised to upgrade to the latest versions, which contain necessary security patches.

Affected Version(s)

QTS 5.2.x < 5.2.4.3079 build 20250321

QuTS hero h5.2.x

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Searat and izut
.