Multiple Flaws in QNAP Tools Allow Attackers to Steal Sensitive Data
ID: ba77fc6b-a99d-52e7-8223-36b234bd6720
STIX ID: report--ba77fc6b-a99d-52e7-8223-36b234bd6720
Feed Name: GBHackers
Threat Score
QNAP released an advisory for License Center 2.0.x addressing two memory-management vulnerabilities: CVE-2025-52871 (out-of-bounds read allowing authenticated users to access secret data) and CVE-2025-53597 (buffer overflow requiring administrator privileges that can modify memory or crash processes). Both are rated Moderate; QNAP advises updating to License Center version 2.0.36 or later via QTS/QuTS Hero App Center to mitigate these issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
