Buffer Overflow Vulnerability in QNAP Operating Systems
CVE-2025-52863

1.3LOW

Key Information:

Vendor

QNAP

Vendor
CVE Published:
2 January 2026

What is CVE-2025-52863?

A buffer overflow vulnerability has been identified in several versions of QNAP operating systems. This flaw allows an attacker with user account access to exploit the system, potentially resulting in unauthorized memory modifications or process crashes. Immediate action is required to upgrade to the latest versions, ensuring the integrity and security of your systems.

Affected Version(s)

QTS 5.2.x < 5.2.7.3256 build 20250913

QuTS hero h5.2.x

QuTS hero h5.3.x

References

CVSS V4

Score:
1.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

coral
.