QNAP Patches 14 Vulnerabilities in QTS, QuTS hero, and QVP Devices
ID: 9ebc89fc-42fe-5c3c-9906-ab9995c4a427
STIX ID: report--9ebc89fc-42fe-5c3c-9906-ab9995c4a427
Feed Name: securityonline.info
**TL;DR:** QNAP released patches for 14 vulnerabilities across QTS, QuTS hero, QuTS cloud, and QVP — including multiple command-injection flaws, a URL-injection credential theft bug (CVE-2025-59382), pre-auth NULL-pointer and other denial-of-service issues, and buffer overflows; most require authentication but some are exploitable without login. Administrators should apply the published firmware updates, restrict admin access, keep management interfaces off the public internet, and maintain offline backups and snapshots.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
