A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later
2024-11-22T16:15:23.143
2025-09-23T12:07:48.633
Analyzed
CVSSv3.1: 4.9 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | qnap | qts | 5.2.0.2737 | Yes |
| Operating System | qnap | qts | 5.2.0.2744 | Yes |
| Operating System | qnap | qts | 5.2.0.2782 | Yes |
| Operating System | qnap | qts | 5.2.0.2802 | Yes |
| Operating System | qnap | qts | 5.2.0.2823 | Yes |
| Operating System | qnap | qts | 5.2.0.2851 | Yes |
| Operating System | qnap | qts | 5.2.0.2860 | Yes |
| Operating System | qnap | quts_hero | h5.2.0.2737 | Yes |
| Operating System | qnap | quts_hero | h5.2.0.2782 | Yes |
| Operating System | qnap | quts_hero | h5.2.0.2789 | Yes |
| Operating System | qnap | quts_hero | h5.2.0.2802 | Yes |
| Operating System | qnap | quts_hero | h5.2.0.2823 | Yes |
| Operating System | qnap | quts_hero | h5.2.0.2851 | Yes |
| Operating System | qnap | quts_hero | h5.2.0.2860 | Yes |