CVE-2025-59385

CWE-2903 documents3 sources
Severity
8.1HIGH
EPSS
0.6%
top 31.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16

Description

An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages4 packages

CVEListV5qnap_systems_inc./quts_heroh5.2.xh5.2.7.3297 build 20251024+1
NVDqnap/quts_hero20 versions+19
CVEListV5qnap_systems_inc./qts5.2.x5.2.7.3297 build 20251024
NVDqnap/qts17 versions+16

🔴Vulnerability Details

2
GHSA
GHSA-xggh-gjh3-26r2: An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions2025-12-16
CVEList
QTS, QuTS hero2025-12-16
CVE-2025-59385 (HIGH CVSS 8.1) | An authentication bypass by spoofin | cvebase.io