VDB

CVE-2025-59385

CVE-2025-59385 PUBLISHED CVSS 8.100000381469727 HIGH

An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later

EPSS 0.60% · 69.9th percentile

Risk Scores

CVSS 4.0
8.100000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
EPSS Score
0.60%
69.9th percentile

Affected Products

VendorProductVersions
qnap_systems_inc.quts_heroh5.3.x, *
qnapqts5.2.0.2737, 5.2.0.2782, 5.2.0.2802
qnap_systems_inc.qts5.2.x
qnapquts_hero*, h5.2.0.2737, h5.2.0.2782
QNAP Systems Inc.QTS5.2.x
QNAP Systems Inc.QuTS heroh5.2.x, h5.3.x

Timeline

  • Sep 15, 2025 CVE ID Reserved
  • Dec 16, 2025 EPSS Score
  • Dec 16, 2025 CVE Published
  • Dec 20, 2025 EPSS Score
  • Dec 24, 2025 EPSS Score
  • Dec 28, 2025 EPSS Score
  • Jan 1, 2026 EPSS Score
  • Jan 5, 2026 EPSS Score
  • Jan 9, 2026 EPSS Score
  • Jan 13, 2026 EPSS Score
  • Jan 17, 2026 EPSS Score
  • Jan 21, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›