Null Pointer Dereference Vulnerability in QNAP Operating Systems
CVE-2025-30267
5.3MEDIUM
What is CVE-2025-30267?
A vulnerability exists in QNAP operating systems where a NULL pointer dereference can be exploited by an attacker with a user account. This attack can lead to a denial-of-service (DoS) condition, disrupting service availability. Users are strongly encouraged to upgrade to QTS 5.2.5.3145 build 20250526 or later, and QuTS hero h5.2.5.3138 build 20250519 or later to mitigate this risk.
Affected Version(s)
QTS 5.2.x < 5.2.5.3145 build 20250526
QuTS hero h5.2.x