CVE-2025-66276 PUBLISHED

QTS

Assigner: qnap
Reserved: 26.11.2025 Published: 10.06.2026 Updated: 10.06.2026

QuTS hero is not affected.

We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor QNAP Systems Inc.
Product QTS
Versions Default: unaffected
  • affected from 5.2.0 to 5.2.7.3256 build 20250913 (excl.)
Vendor QNAP Systems Inc.
Product QuTS hero
Versions Default: unaffected
  • Version ? is unaffected

Solutions

We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

Credits

  • Víctor A. Morales finder

References