AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2025-59385.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.1CVSS 4.0 · security@qnapsecurity.com.tw
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSAnalyzedModified Oct 07, 2026

Disclosure summary

An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later

Source-reported weakness categories

CWE-290

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2025-59385

Open original source · Updated Oct 07, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

VendorProduct / associationVersion / bounds
qnapqts5.2.0.2737
qnapqts5.2.0.2744
qnapqts5.2.0.2782
qnapqts5.2.0.2802
qnapqts5.2.0.2823
qnapqts5.2.0.2851
qnapqts5.2.0.2860
qnapqts5.2.1.2930
qnapqts5.2.2.2950
qnapqts5.2.3.3006
qnapqts5.2.4.3070
qnapqts5.2.4.3079
qnapqts5.2.4.3092
qnapqts5.2.5.3145
qnapqts5.2.6.3195
qnapqts5.2.6.3229
qnapqts5.2.7.3256
qnapquts_heroh5.2.0.2737
qnapquts_heroh5.2.0.2782
qnapquts_heroh5.2.0.2789
qnapquts_heroh5.2.0.2802
qnapquts_heroh5.2.0.2823
qnapquts_heroh5.2.0.2851
qnapquts_heroh5.2.0.2860
qnapquts_heroh5.2.1.2929
qnapquts_heroh5.2.1.2940
qnapquts_heroh5.2.2.2952
qnapquts_heroh5.2.3.3006
qnapquts_heroh5.2.4.3070
qnapquts_heroh5.2.4.3079
qnapquts_heroh5.2.5.3138
qnapquts_heroh5.2.6.3195
qnapquts_heroh5.2.7.3256
qnapquts_heroh5.3.0.3115
qnapquts_heroh5.3.0.3145
qnapquts_heroh5.3.0.3192
qnapquts_heroh5.3.1.3250

Original records & references

PUBLISHED 2025-12-15T22:15:58-05:00
MODIFIED 2026-10-07T15:10:00-04:00
INGESTED 2026-10-08T12:35:47-04:00