CVE-2025-59385
CRITICALQnap Qts - Authentication Bypass by Spoofing
Title source: ruleDescription
An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later
Scores
CVSS v3
9.8
EPSS
0.0056
EPSS Percentile
68.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-290
Status
published
Affected Products (37)
qnap/qts
qnap/qts
qnap/qts
qnap/qts
qnap/qts
qnap/qts
qnap/qts
qnap/qts
qnap/qts
qnap/qts
qnap/qts
qnap/qts
qnap/qts
qnap/qts
qnap/qts
... and 22 more
Timeline
Published
Dec 16, 2025
Tracked Since
Feb 18, 2026