PT-2026-48357 · Qnap · Qts
CVE-2025-66276
·
Published
2026-06-10
·
Updated
2026-06-12
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
QTS versions prior to 5.2.7.3256 build 20250913
Description
An access-control flaw exists in legacy environments where the NFS (Network File System) service is enabled. When NFS share settings are permissive, specifically using a wildcard host entry and no user squashing, an attacker can perform unauthorized actions on exported shares and potentially access data on the NAS. This issue is network-reachable and requires no authentication or user interaction to exploit.
Recommendations
Update to version 5.2.7.3256 build 20250913 or later.
Harden NFS share permissions by replacing wildcard hosts with specific IP addresses and enabling the Squash all users option.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qts