NULL Pointer Dereference in QNAP Operating Systems
CVE-2025-30274
5.1MEDIUM
What is CVE-2025-30274?
A NULL pointer dereference vulnerability has been reported in multiple versions of QNAP operating systems, potentially allowing attackers to exploit the flaw. This exploitation could lead to a denial-of-service (DoS) condition, disrupting the normal functionality of the affected systems. Users are advised to upgrade to QTS 5.2.5.3145 build 20250526 and later, or QuTS hero h5.2.5.3138 build 20250519 and later, to mitigate this issue.
Affected Version(s)
QTS 5.2.x < 5.2.5.3145 build 20250526
QuTS hero h5.2.x