Command Injection Flaw in QNAP Operating Systems
CVE-2025-62847

6.6MEDIUM

Key Information:

Vendor

QNAP

Vendor
CVE Published:
16 December 2025

What is CVE-2025-62847?

A command injection vulnerability has been identified in various versions of the QNAP operating system. This flaw arises from inadequate neutralization of argument delimiters, allowing remote attackers to manipulate the control flow of the application. Successful exploitation could lead to unauthorized changes in execution logic, posing significant risks to system integrity and security. QNAP has released updates in QTS and QuTS hero to remediate this issue.

Affected Version(s)

QTS 5.2.x < 5.2.7.3297 build 20251024

QuTS hero h5.2.x

QuTS hero h5.3.x

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pwn2Own 2025 - DEVCORE
.
CVE-2025-62847 : Command Injection Flaw in QNAP Operating Systems