A use of externally-controlled format string...
Moderate severity
Unreviewed
Published
Oct 3, 2025
to the GitHub Advisory Database
•
Updated Oct 8, 2025
Description
Published by the National Vulnerability Database
Oct 3, 2025
Published to the GitHub Advisory Database
Oct 3, 2025
Last updated
Oct 8, 2025
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.6.3195 build 20250715 and later
QuTS hero h5.2.6.3195 build 20250715 and later
References