CVE-2025-59382Patch

MEDIUMCVSS 1.2 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-472

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-06-29); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-29: 1Mentions · 2026-07-05: 1PoC Mentioned / Linked · 2026-07-05: 1Exploit Tool / Code · 2026-07-05: 1Patch / Workaround · 2026-06-29: 1Technical Details · 2026-06-29: 106-2907-05
Signal classification2 categories
Patch
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-291
Patch1
2026-07-051
PoC1
Full discourse2 posts
  • nad@Nadsec11
    PoC

    https://github.com/Rat5ak/CVE-2025-59382-QNAP-Password-Reset-Account-Takeover A kwl 1

    Post summary

    A GitHub repository appears to host a proof‑of‑concept exploit for CVE‑2025‑59382, a QNAP password‑reset account takeover vulnerability.

    02074638
    701 followersView on X
  • iototsecnews@iototsecnews
    Patch

    QNAP NAS 製品群の複数の深刻な脆弱性が FIX:認証情報窃取や DoS などの恐れ https://iototsecnews.jp/2026/06/22/qnap-fixes-14-vulnerabilities-in-qts-quts-hero-quts-cloud-and-qvp/ 今回の QNAP のアドバイザリは、URL インジェクションの欠陥 CVE-2025-59382 や、入力サニタイズの不備によるコマンド・インジェクション CVE-2025-66273/CVE-2025-66279 などに対処するものです。また、メモリ処理の不適切な取り扱いから生じるバッファ・オーバーフロー CVE-2026-26241/NULL ポインタ逆参照 CVE-2026-22899/アクセス制御の不備も修正されています。ご利用のチームは、ご注意ください。 #CVE202559382 #CVE202562858 #CVE202566273 #CVE202566279 #CVE202566280 #CVE202566281 #CVE202568405 #CVE202622893 #CVE202622899 #CVE202624720 #CVE202624724 #CVE202626239 #CVE202626240 #CVE202626241 #NAS #QNAP #Vulnerability

    Post summary

    QNAP’s advisory announces fixes for 14 critical vulnerabilities, including URL injection, command injection, buffer overflow, NULL pointer dereference, and access control issues.

    01000163
    500 followersView on X

Explore more