Path Traversal Vulnerability in QNAP Operating System
CVE-2025-47211
6.9MEDIUM
What is CVE-2025-47211?
A path traversal vulnerability has been identified in QNAP's operating system, allowing a remote attacker with administrator credentials to traverse directories and access sensitive files or system data that should remain protected. This weakness highlights the importance of securing admin accounts and keeping software updated. QNAP has released fixes in version 5.2.6.3195 build 20250715 and later for both QTS and QuTS hero systems.
Affected Version(s)
QTS 5.2.x < 5.2.6.3195 build 20250715
QuTS hero h5.2.x