PT-2026-48363 · Qnap · Quts Hero+1
CVE-2025-66281
·
Published
2026-06-10
·
Updated
2026-07-07
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
QTS versions prior to 5.2.9.3410 build 20260214
QuTS hero versions prior to h5.2.9.3410 build 20260214
QuTS hero versions prior to h5.3.4.3500 build 20260520
QuTS hero versions prior to h6.0.0.3397 build 20260206
Description
A NULL pointer dereference occurs in several QNAP operating system versions, which remote attackers can exploit to launch a denial-of-service (DoS) attack. A NULL pointer dereference happens when a program attempts to read or write to a memory address that is NULL, typically causing the application to crash.
Recommendations
Update to QTS 5.2.9.3410 build 20260214 or later.
Update to QuTS hero h5.2.9.3410 build 20260214 or later.
Update to QuTS hero h5.3.4.3500 build 20260520 or later.
Update to QuTS hero h6.0.0.3397 build 20260206 or later.
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qts
Quts Hero