
[ZDI-26-199|CVE-2025-62848] (Pwn2Own) QNAP TS-453E conn_log_tool Format String Remote Code Execution Vulnerability (CVSS 5.5; Credit: @YingMuo, @ljp_tw, @h3xr4bb1t, and @nella17tw of DEVCORE Research Team) https://www.zerodayinitiative.com/advisories/ZDI-26-199/
Post summary
The post announces a format‑string RCE vulnerability in QNAP TS‑453E, credits the researchers, links to a Zero Day Initiative advisory which likely contains a PoC, but does not disclose active exploitation, patches, or detailed exploitation tools.
