Description
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system.

We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and later
QuTS hero h5.2.9.3410 build 20260214 and later
QuTS hero h5.3.4.3500 build 20260520 and later
QuTS hero h6.0.0.3397 build 20260206 and later
Published: 2026-06-10
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow or wraparound flaw exists in QNAP's QTS and QuTS hero operating systems. The weakness allows a malicious actor who has gained an administrator account to exploit memory handling logic, potentially altering program execution flow or corrupting data. This can lead to unauthorized system compromise, data theft, or further escalation of privileges. The flaw is formally categorized under CWE‑121 (Stack-based Buffer Overflow) and CWE‑190 (Integer Overflow or Wraparound).

Affected Systems

The vulnerability affects QNAP Systems Inc.'s QTS and QuTS hero firmware. Specifically, any install of QTS older than build 20260214 in version 5.2.9.3410 or later releases, QuTS hero h5.2.9.3410 earlier than build 20260214, QuTS hero h5.3.4.3500 before build 20260520, and QuTS hero h6.0.0.3397 prior to build 20260206 are susceptible. Firmware versions before these builds lack the necessary patch to prevent the overflow.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires remote access combined with an administrative account, meaning attackers that can compromise or guess admin credentials can potentially launch the overflow attack. Because the flaw involves integer handling, a successful exploit could allow arbitrary code execution or arbitrary privilege escalation on the affected device.

Generated by OpenCVE AI on June 10, 2026 at 04:23 UTC.

Remediation

Vendor Solution

We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3397 build 20260206 and later


OpenCVE Recommended Actions

  • Upgrade the device to the latest QTS or QuTS hero firmware that contains the defined patch, ensuring the build numbers match the vendor’s official release list.
  • Limit the use of administrator accounts; disable or repurpose any accounts that are not required for day‑to‑day operations.
  • Segment the network so that QNAP devices are isolated from untrusted subnets, and monitor for anomalous activity that may indicate exploitation attempts.

Generated by OpenCVE AI on June 10, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 03:45:00 +0000

Type Values Removed Values Added
Description An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3397 build 20260206 and later
Title QTS, QuTS hero
Weaknesses CWE-121
CWE-190
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2026-06-10T03:05:59.942Z

Reserved: 2025-11-26T09:25:37.833Z

Link: CVE-2025-66280

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-10T04:17:12.420

Modified: 2026-06-10T04:17:12.420

Link: CVE-2025-66280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T04:30:06Z

Weaknesses