QNAP Addresses 14 Vulnerabilities in NAS and Surveillance Systems

QNAP Addresses 14 Vulnerabilities in NAS and Surveillance Systems

8h ago CybersecuritynewsGbhackerswww.qnap.com 81% similarity 57.9
Share:

Article Content

Browse articles
ThreatCluster

QNAP has released security advisory QSA-26-10 to address 14 vulnerabilities in its NAS and surveillance platforms, including QTS, QuTS hero, QuTS cloud, and QVP (QVR Pro appliances). These vulnerabilities, disclosed on April 6, 2026, are categorized as having 'Important' severity. Notable issues include CVE-2025-59382, a URL injection flaw that could lead to credential harvesting, and several command injection vulnerabilities (CVE-2025-66273, CVE-2025-66279, CVE-2026-22893) that allow arbitrary command execution. Other critical vulnerabilities involve memory safety issues, such as stack and buffer overflows (CVE-2025-62858, CVE-2026-26239, CVE-2026-26241), which can cause service crashes. QNAP has released firmware updates to mitigate these vulnerabilities, urging users to update immediately to prevent exploitation. The vulnerabilities affect versions QTS 5.2.7, QuTS hero h5.2.8, QuTS cloud c5.2.8, and QVP 2.7.1.

Key Points: • QNAP fixed 14 vulnerabilities in its NAS and surveillance systems with advisory QSA-26-10. • Critical vulnerabilities include command injection and memory safety issues, allowing potential system compromise. • Users are urged to update to the latest firmware versions to mitigate risks of exploitation.

ThreatCluster AI

Timeline

2026-04-06
Vulnerabilities disclosed
QNAP reported 14 vulnerabilities affecting its NAS and surveillance platforms, categorized as 'Important'.
Gbhackers
2026-06-09
CVE-2025-62858 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2026-22899 published
A NULL pointer dereference vulnerability was published, exploitable by low-privileged users.
Gbhackers
2026-06-10
CVE-2026-26240 published
A buffer overflow vulnerability was published, allowing potential service crashes.
Gbhackers
2026-06-10
CVE-2025-59382 published
A URL injection flaw was published, which could lead to credential harvesting.
Gbhackers
2026-06-10
CVE-2025-66281 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2026-22893 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2026-26239 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2026-24724 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2025-66273 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →