216.73.216.6

CVE-2025-59385

· Published 16/12/2025 03:15 · Modified 17/12/2025 14:00

Labels: CVE-2025-59385 2025-12-16CVE-2025-59385[email protected]

Essential information

Published
16/12/2025 03:15
Modified
17/12/2025 14:00
Author
Creator
CVSS
8.1 HIGH (v3) 8.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
qnap / qts cpe:2.3:o:qnap:qts:5.2.0.2737:build_20240417:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.0.2744:build_20240424:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.0.2782:build_20240601:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.0.2802:build_20240620:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.0.2823:build_20240711:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.0.2851:build_20240808:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.0.2860:build_20240817:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.1.2930:build_20241025:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.2.2950:build_20241114:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.3.3006:build_20250108:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.4.3070:build_20250312:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.4.3079:build_20250321:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.4.3092:build_20250403:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.5.3145:build_20250526:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.6.3195:build_20250715:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.6.3229:build_20250818:*:*:*:*:*:*
qnap / qts cpe:2.3:o:qnap:qts:5.2.7.3256:build_20250913:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.0.2737:build_20240417:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.0.2782:build_20240601:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.0.2789:build_20240607:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.0.2802:build_20240620:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.0.2823:build_20240711:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.0.2851:build_20240808:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.0.2860:build_20240817:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.1.2929:build_20241025:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.1.2940:build_20241105:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.2.2952:build_20241116:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.3.3006:build_20250108:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.4.3070:build_20250312:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.4.3079:build_20250321:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.5.3138:build_20250519:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.6.3195:build_20250715:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.2.7.3256:build_20250913:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.3.0.3115:build_20250430:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.3.0.3145:build_20250530:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.3.0.3192:build_20250716:*:*:*:*:*:*
qnap / quts hero cpe:2.3:o:qnap:quts_hero:h5.3.1.3250:build_20250912:*:*:*:*:*:*

References