
https://github.com/Rat5ak/CVE-2025-59382-QNAP-Password-Reset-Account-Takeover A kwl 1
Post summary
A GitHub repository appears to host a proof‑of‑concept exploit for CVE‑2025‑59382, a QNAP password‑reset account takeover vulnerability.
Exploit discussion active in current signal (1 latest mentions)
Recommended action window: High priority (within 72h)
NVD description
QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
Priority
MEDIUM
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
| Date | Total | Labels |
|---|
| 2026-06-29 | 1 | Patch1 |
| 2026-07-05 | 1 | PoC1 |

https://github.com/Rat5ak/CVE-2025-59382-QNAP-Password-Reset-Account-Takeover A kwl 1
Post summary
A GitHub repository appears to host a proof‑of‑concept exploit for CVE‑2025‑59382, a QNAP password‑reset account takeover vulnerability.

QNAP NAS 製品群の複数の深刻な脆弱性が FIX:認証情報窃取や DoS などの恐れ https://iototsecnews.jp/2026/06/22/qnap-fixes-14-vulnerabilities-in-qts-quts-hero-quts-cloud-and-qvp/ 今回の QNAP のアドバイザリは、URL インジェクションの欠陥 CVE-2025-59382 や、入力サニタイズの不備によるコマンド・インジェクション CVE-2025-66273/CVE-2025-66279 などに対処するものです。また、メモリ処理の不適切な取り扱いから生じるバッファ・オーバーフロー CVE-2026-26241/NULL ポインタ逆参照 CVE-2026-22899/アクセス制御の不備も修正されています。ご利用のチームは、ご注意ください。 #CVE202559382 #CVE202562858 #CVE202566273 #CVE202566279 #CVE202566280 #CVE202566281 #CVE202568405 #CVE202622893 #CVE202622899 #CVE202624720 #CVE202624724 #CVE202626239 #CVE202626240 #CVE202626241 #NAS #QNAP #Vulnerability
Post summary
QNAP’s advisory announces fixes for 14 critical vulnerabilities, including URL injection, command injection, buffer overflow, NULL pointer dereference, and access control issues.