Use of Externally-Controlled Format String Vulnerability in QNAP Operating Systems
CVE-2025-53407

5.1MEDIUM

Key Information:

Vendor

QNAP

Vendor
CVE Published:
3 October 2025

What is CVE-2025-53407?

A vulnerability has been identified in several QNAP operating system versions which allows a remote attacker, with administrative access, to exploit a use of externally-controlled format string. This could potentially lead to unauthorized access to sensitive data or modification of system memory, posing significant security risks. QNAP has released a fix in QTS and QuTS hero versions 5.2.6.3195 build 20250715 and later.

Affected Version(s)

QTS 5.2.x < 5.2.6.3195 build 20250715

QuTS hero h5.2.x

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

coral
.
CVE-2025-53407 : Use of Externally-Controlled Format String Vulnerability in QNAP Operating Systems