CVE-2025-59382
LOWQNAP Systems - QTS, QuTS Hero, QuTScloud, QVP (QVR Pro Appliances)
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2025-59382. PoCs published by Rat5ak.
AI-analyzed exploit summary This repository demonstrates a full exploit chain for CVE-2025-59382, a URL injection vulnerability in QNAP's password reset mechanism. The exploit allows unauthenticated attackers to inject arbitrary URLs into password reset emails, enabling account takeover by intercepting reset tokens and verification codes.
Description
QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
Exploits (1)
This repository demonstrates a full exploit chain for CVE-2025-59382, a URL injection vulnerability in QNAP's password reset mechanism. The exploit allows unauthenticated attackers to inject arbitrary URLs into password reset emails, enabling account takeover by intercepting reset tokens and verification codes.
References (1)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X