PT-2026-48363 · Qnap · Quts Hero+1

CVE-2025-66281

·

Published

2026-06-10

·

Updated

2026-07-07

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QTS versions prior to 5.2.9.3410 build 20260214 QuTS hero versions prior to h5.2.9.3410 build 20260214 QuTS hero versions prior to h5.3.4.3500 build 20260520 QuTS hero versions prior to h6.0.0.3397 build 20260206
Description A NULL pointer dereference occurs in several QNAP operating system versions, which remote attackers can exploit to launch a denial-of-service (DoS) attack. A NULL pointer dereference happens when a program attempts to read or write to a memory address that is NULL, typically causing the application to crash.
Recommendations Update to QTS 5.2.9.3410 build 20260214 or later. Update to QuTS hero h5.2.9.3410 build 20260214 or later. Update to QuTS hero h5.3.4.3500 build 20260520 or later. Update to QuTS hero h6.0.0.3397 build 20260206 or later.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66281

Affected Products

Qts
Quts Hero