Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xhj9-wqh5-g6hq

Опубликовано: 02 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.7
CVSS3: 7.5

Описание

An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to read application data.

We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later QuTS hero h5.3.1.3250 build 20250912 and later

An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to read application data.

We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later QuTS hero h5.3.1.3250 build 20250912 and later

EPSS

Процентиль: 19%
0.0006
Низкий

2.7 Low

CVSS4

7.5 High

CVSS3

Дефекты

CWE-497

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later QuTS hero h5.3.1.3250 build 20250912 and later

EPSS

Процентиль: 19%
0.0006
Низкий

2.7 Low

CVSS4

7.5 High

CVSS3

Дефекты

CWE-497