216.73.216.197

CVE-2025-52872

· Published 02/01/2026 15:16 · Modified 02/01/2026 16:45

Labels: CVE-2025-52872 2026-01-02CVE-2025-52872CWE-120[email protected]

Essential information

Published
02/01/2026 15:16
Modified
02/01/2026 16:45
Author
Creator
CVSS
1.3 LOW (v3) 1.3 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.0.3192 build 20250716 and later

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
qnap / qts cpe:2.3:o:qnap:qts:5.2.7.3256:*:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.7.3256:*:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.3.0.3192:*:*:*:*:*:*:*

References