216.73.216.133

CVE-2025-53591

· Published 02/01/2026 15:16 · Modified 02/01/2026 16:45

Labels: CVE-2025-53591 2026-01-02CVE-2025-53591CWE-134[email protected]

Essential information

Published
02/01/2026 15:16
Modified
02/01/2026 16:45
Author
Creator
CVSS
1.2 LOW (v3) 1.2 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
qnap / qts cpe:2.3:o:qnap:qts:5.2.7.3256:*:*:*:*:*:*:*
qnap / quTS hero cpe:2.3:o:qnap:quTS_hero:h5.2.7.3256:*:*:*:*:*:*:*
qnap / quTS hero cpe:2.3:o:qnap:quTS_hero:h5.3.1.3250:*:*:*:*:*:*:*

References