TROYANOSYVIRUS
Retour aux CVEs

CVE-2025-66274

MEDIUM
4.9

Description

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build 20251225 and later

Details CVE

Score CVSS v3.14.9
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie2/11/2026
Derniere modification2/12/2026
Sourcenvd
Observations honeypot0

Produits affectes

qnap:quts_hero

Faiblesses (CWE)

CWE-476

References

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.