SQL Injection Vulnerability in QNAP Operating Systems
CVE-2025-62849

5.2MEDIUM

Key Information:

Vendor

QNAP

Vendor
CVE Published:
16 December 2025

What is CVE-2025-62849?

An SQL injection vulnerability has been discovered in several versions of QNAP operating systems, allowing remote attackers to execute unauthorized commands or code. By exploiting this flaw, malicious users can manipulate the database queries to gain control over the system. QNAP has released updates to remediate this issue in QTS and QuTS hero systems. Users are advised to upgrade to the specified builds to ensure their systems remain secure.

Affected Version(s)

QTS 5.2.x < 5.2.7.3297 build 20251024

QuTS hero h5.2.x

QuTS hero h5.3.x

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pwn2Own 2025 - DEVCORE
.
CVE-2025-62849 : SQL Injection Vulnerability in QNAP Operating Systems