← All CVEs

CVE-2025-66277

critical · 9.2

A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3350 build 20251216 and later QuTS hero h5.3.2.3354 build 20251225 and later QuTS hero h5.2.8.3350 build 20251216 and later

9.2
CVSS
0.7%
EPSS (exploit prob.)
50th
EPSS percentile
2026-02-11
Published

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weaknesses

CWE-59

Affected products

VendorProductAffected versions
qnapqts5.2.0.2737
qnapqts5.2.0.2744
qnapqts5.2.0.2782
qnapqts5.2.0.2802
qnapqts5.2.0.2823
qnapqts5.2.0.2851
qnapqts5.2.0.2860
qnapqts5.2.1.2930
qnapqts5.2.2.2950
qnapqts5.2.3.3006
qnapqts5.2.4.3070
qnapqts5.2.4.3079
qnapqts5.2.4.3092
qnapqts5.2.5.3145
qnapqts5.2.6.3195
qnapqts5.2.6.3229
qnapqts5.2.7.3256
qnapqts5.2.7.3297
qnapqts5.2.8.3332
qnapquts_heroh5.2.0.2737
qnapquts_heroh5.2.0.2782
qnapquts_heroh5.2.0.2789
qnapquts_heroh5.2.0.2802
qnapquts_heroh5.2.0.2823
qnapquts_heroh5.2.0.2851
qnapquts_heroh5.2.0.2860
qnapquts_heroh5.2.1.2929
qnapquts_heroh5.2.1.2940
qnapquts_heroh5.2.2.2952
qnapquts_heroh5.2.3.3006
qnapquts_heroh5.2.4.3070
qnapquts_heroh5.2.4.3079
qnapquts_heroh5.2.5.3138
qnapquts_heroh5.2.6.3195
qnapquts_heroh5.2.7.3256
qnapquts_heroh5.2.7.3297
qnapquts_heroh5.2.8.3321

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-66277