VDB

GCVE-110-NCSC-2025-403

GCVE-110-NCSC-2025-403
Advisory PublishedCVSS 7.5/10
Vulnetix · Advisory published December 29, 2025
A vulnerability in multiple QNAP operating system versions allows remote attackers to manipulate execution logic due to improper argument delimiter handling, now resolved in specific QTS and QuTS hero versions.

Weaknesses (CWE)

CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')CWE-476NULL Pointer DereferenceCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-290Authentication Bypass by Spoofing

Risk Scores

CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersionsPlatforms
QNAPvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,237 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›