logo

Multiple Flaws in QNAP Tools Allow Attackers to Steal Sensitive Data

ID: ba77fc6b-a99d-52e7-8223-36b234bd6720

STIX ID: report--ba77fc6b-a99d-52e7-8223-36b234bd6720

Feed Name: GBHackers

Threat Score
50/100

Date Published: 2026-01-05

Date Updated: 2026-04-22

Author: Divya

...
...

QNAP released an advisory for License Center 2.0.x addressing two memory-management vulnerabilities: CVE-2025-52871 (out-of-bounds read allowing authenticated users to access secret data) and CVE-2025-53597 (buffer overflow requiring administrator privileges that can modify memory or crash processes). Both are rated Moderate; QNAP advises updating to License Center version 2.0.36 or later via QTS/QuTS Hero App Center to mitigate these issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.