Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-30271


A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later


Published

2025-08-29T18:15:39.360

Last Modified

2025-09-22T14:48:58.443

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qnap qts 5.2.0.2737 Yes
Operating System qnap qts 5.2.0.2744 Yes
Operating System qnap qts 5.2.0.2782 Yes
Operating System qnap qts 5.2.0.2802 Yes
Operating System qnap qts 5.2.0.2823 Yes
Operating System qnap qts 5.2.0.2851 Yes
Operating System qnap qts 5.2.0.2860 Yes
Operating System qnap qts 5.2.1.2930 Yes
Operating System qnap qts 5.2.2.2950 Yes
Operating System qnap qts 5.2.3.3006 Yes
Operating System qnap qts 5.2.4.3070 Yes
Operating System qnap qts 5.2.4.3079 Yes
Operating System qnap qts 5.2.4.3092 Yes
Operating System qnap quts_hero h5.2.0.2737 Yes
Operating System qnap quts_hero h5.2.0.2782 Yes
Operating System qnap quts_hero h5.2.0.2789 Yes
Operating System qnap quts_hero h5.2.0.2802 Yes
Operating System qnap quts_hero h5.2.0.2823 Yes
Operating System qnap quts_hero h5.2.0.2851 Yes
Operating System qnap quts_hero h5.2.0.2860 Yes
Operating System qnap quts_hero h5.2.1.2929 Yes
Operating System qnap quts_hero h5.2.1.2940 Yes
Operating System qnap quts_hero h5.2.2.2952 Yes
Operating System qnap quts_hero h5.2.3.3006 Yes
Operating System qnap quts_hero h5.2.4.3070 Yes
Operating System qnap quts_hero h5.2.4.3079 Yes

References