CVE-2025-47208

MEDIUM

QNAP QTS and QuTS hero - Authenticated Denial of Service via Resource Exhaustion

Title source: llm
STIX 2.1

Description

An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.2.6.3195 build 20250715 and later

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0021
EPSS Percentile 42.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (34)
qnap/qts 5.2.0.2737 build_20240417
qnap/qts 5.2.0.2744 build_20240424
qnap/qts 5.2.0.2782 build_20240601
qnap/qts 5.2.0.2802 build_20240620
qnap/qts 5.2.0.2823 build_20240711
qnap/qts 5.2.0.2851 build_20240808
qnap/qts 5.2.0.2860 build_20240817
qnap/qts 5.2.1.2930 build_20241025
qnap/qts 5.2.2.2950 build_20241114
qnap/qts 5.2.3.3006 build_20250108
... and 24 more
Published Jan 02, 2026
Tracked Since Feb 18, 2026