Description
QTS, QuTS hero, QuTScloud are not affected.

We have already fixed the vulnerability in the following version:
Published: 2026-06-10
Score: 1.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw corresponds to CWE‑472, which deals with the use of untrusted file types during file handling. This weakness can allow an attacker to access or process files that should be restricted, potentially exposing sensitive data or enabling code execution if the files trigger vulnerabilities in the application. The advisory notes that QTS, QuTS hero and QuTScloud themselves are not affected, yet the CNA lists them as affected, creating a discrepancy that leaves the exact impact unclear. The CVSS score of 1.2 places this vulnerability in the low range, and no exploitation has been reported in the advisory or the CVE entry.

Affected Systems

The CNA identifies QNAP Systems Inc. products QTS, QuTS hero, and QuTScloud as affected, but the vendor’s advisory explicitly states those systems are not impacted. No specific versions are listed, so administrators cannot confirm whether their devices have the fix or are still susceptible. The broader category may include QVP (QVR Pro appliances), but details are not provided.

Risk and Exploitability

With a 1.2 CVSS score and an EPSS of < 1%, the probability of active exploitation is uncertain, and the vulnerability is not listed in the CISA KEV catalog. The lack of a concrete attack pattern in the advisory suggests a moderate threat level; the most likely vector would involve uploading an untrusted file type that the system processes without proper validation. Until the scope is clearly defined or additional exploits appear, adopting the vendor’s mitigations remains the prudent approach.

Generated by OpenCVE AI on June 12, 2026 at 03:24 UTC.

Remediation

Vendor Solution

We have already fixed the vulnerability in the following version:


OpenCVE Recommended Actions

  • Apply the firmware version referenced in QSA‑26‑10 to close the file‑handling weakness.
  • If a firmware upgrade is not immediately possible, restrict the device’s network exposure and limit file uploads to known, trusted sources only.
  • Enable and review system logs for anomalous file access or processing events that may indicate exploitation attempts.

Generated by OpenCVE AI on June 12, 2026 at 03:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 12 Jun 2026 02:15:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}

cvssV4_0

{'score': 1.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U'}


Wed, 10 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Qnap Systems
Qnap Systems qts
Qnap Systems quts Hero
Qnap Systems qutscloud
Vendors & Products Qnap Systems
Qnap Systems qts
Qnap Systems quts Hero
Qnap Systems qutscloud

Wed, 10 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Description QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
Title QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances)
Weaknesses CWE-472
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Qnap Systems Qts Quts Hero Qutscloud
cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2026-06-12T02:12:53.320Z

Reserved: 2025-09-15T08:35:00.660Z

Link: CVE-2025-59382

cve-icon Vulnrichment

Updated: 2026-06-10T16:03:55.640Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-10T03:16:24.527

Modified: 2026-06-12T02:16:37.467

Link: CVE-2025-59382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T03:30:12Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter