Command Injection Vulnerability in QNAP Operating Systems
CVE-2025-30264
7.7HIGH
What is CVE-2025-30264?
A command injection vulnerability has been identified in multiple versions of QNAP operating systems. This flaw allows remote attackers, who obtain a user account, to execute arbitrary commands on the affected systems. Users are encouraged to update to the latest versions of QTS and QuTS hero to mitigate the risk associated with this vulnerability.
Affected Version(s)
QTS 5.2.x < 5.2.5.3145 build 20250526
QuTS hero h5.2.x