CVE-2025-59382

LOW

QNAP Systems - QTS, QuTS Hero, QuTScloud, QVP (QVR Pro Appliances)

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-59382. PoCs published by Rat5ak.

AI-analyzed exploit summary This repository demonstrates a full exploit chain for CVE-2025-59382, a URL injection vulnerability in QNAP's password reset mechanism. The exploit allows unauthenticated attackers to inject arbitrary URLs into password reset emails, enabling account takeover by intercepting reset tokens and verification codes.

Description

QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:

Exploits (1)

nomisec WORKING POC
by Rat5ak · poc
https://github.com/Rat5ak/CVE-2025-59382-QNAP-Password-Reset-Account-Takeover

This repository demonstrates a full exploit chain for CVE-2025-59382, a URL injection vulnerability in QNAP's password reset mechanism. The exploit allows unauthenticated attackers to inject arbitrary URLs into password reset emails, enabling account takeover by intercepting reset tokens and verification codes.

Classification
Working Poc 98%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: QNAP QuTScloud c5.2.4.3041 build 20250211 (reset_password.cgi)
No auth needed
Prerequisites: Network access to the QNAP NAS management interface (port 8080 by default) · Ability to trigger password reset for a target user (e.g., 'admin') · Victim interaction (clicking the malicious link or entering verification code on attacker-controlled page)
mistral-large-3 · analyzed Jul 05, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v4 1.2
EPSS 0.0037
EPSS Percentile 29.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-472
Status published
Products (3)
QNAP Systems Inc./QTS ?
QNAP Systems Inc./QuTS hero ?
QNAP Systems Inc./QuTScloud c5.0.0
Published Jun 10, 2026
Tracked Since Jun 10, 2026