Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66280

Опубликовано: 10 июн. 2026
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system.

We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3397 build 20260206 and later

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*
Версия от 5.2.0.2737 (включая) до 5.2.9.3410 (исключая)
cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*
Версия от h5.2.0.2737 (включая) до h5.2.9.3410 (исключая)
cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*
Версия от h5.3.0.3115 (включая) до h5.3.4.3500 (исключая)
cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:*
Версия от h6.0.0.3324 (включая) до h6.0.0.3397 (исключая)

EPSS

Процентиль: 36%
0.00435
Низкий

7.2 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 7.2
github
около 2 месяцев назад

An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3397 build 20260206 and later

EPSS

Процентиль: 36%
0.00435
Низкий

7.2 High

CVSS3

Дефекты

CWE-121