VDB
CVE-2025-59385
CVE-2025-59385
PUBLISHED
CVSS 8.100000381469727 HIGH
An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later
EPSS 0.60% · 69.9th percentile
Risk Scores
CVSS 4.0
8.100000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
EPSS Score
0.60%
69.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| qnap_systems_inc. | quts_hero | h5.3.x, * |
| qnap | qts | 5.2.0.2737, 5.2.0.2782, 5.2.0.2802 |
| qnap_systems_inc. | qts | 5.2.x |
| qnap | quts_hero | *, h5.2.0.2737, h5.2.0.2782 |
| QNAP Systems Inc. | QTS | 5.2.x |
| QNAP Systems Inc. | QuTS hero | h5.2.x, h5.3.x |
Timeline
- Sep 15, 2025 CVE ID Reserved
- Dec 16, 2025 EPSS Score
- Dec 16, 2025 CVE Published
- Dec 20, 2025 EPSS Score
- Dec 24, 2025 EPSS Score
- Dec 28, 2025 EPSS Score
- Jan 1, 2026 EPSS Score
- Jan 5, 2026 EPSS Score
- Jan 9, 2026 EPSS Score
- Jan 13, 2026 EPSS Score
- Jan 17, 2026 EPSS Score
- Jan 21, 2026 EPSS Score