PT-2026-48357 · Qnap · Qts

CVE-2025-66276

·

Published

2026-06-10

·

Updated

2026-06-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QTS versions prior to 5.2.7.3256 build 20250913
Description An access-control flaw exists in legacy environments where the NFS (Network File System) service is enabled. When NFS share settings are permissive, specifically using a wildcard host entry and no user squashing, an attacker can perform unauthorized actions on exported shares and potentially access data on the NAS. This issue is network-reachable and requires no authentication or user interaction to exploit.
Recommendations Update to version 5.2.7.3256 build 20250913 or later. Harden NFS share permissions by replacing wildcard hosts with specific IP addresses and enabling the Squash all users option.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-66276

Affected Products

Qts