CVE-2025-66277Disclosure(qnap / qts)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3350 build 20251216 and later QuTS hero h5.3.2.3354 build 20251225 and later QuTS hero h5.2.8.3350 build 20251216 and later

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • qts
  • quts_hero

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-11); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
qtsquts_hero

37 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-11: 1Mentions · 2026-02-13: 1Mentions · 2026-02-17: 1Technical Details · 2026-02-13: 102-1102-1302-17
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Multiple Critical & High link-following, buffer overflow in #QNAP #NAS #Qsync CVE-2025-66277, CVE-2025-30269, CVE-2025-30276, CVE-2025-48723, CVE-2025-48724, CVE-2025-48725 & CVE-2025-52868 CVSS: 9.2-8.1 A remote attacker without user interaction can exploit these #Patch

    Post summary

    The message warns about multiple critical buffer overflow vulnerabilities affecting QNAP Qsync, enumerating CVE IDs, CVSS scores, and indicating that a remote attacker can exploit them without user interaction.

    01002231
    7.2K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos QNAP ❗ CVE-2025-66277 ➡️ Más info: https://www.cert.gov.py/vulnerabilidaden-productosqnap/ https://t.co/GRTWc178fW

    Post summary

    A new vulnerability (CVE‑2025‑66277) in QNAP products has been announced, with a link provided for further information.

    00001162
    6.6K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in QNAP Systems QTS and QuTS hero (CVE-2025-66277) https://vuldb.com/?id.345481

    Post summary

    A new CVE‑2025‑66277 with elevated criticality has been announced for QNAP Systems QTS and QuTS hero, with further details available at the provided vuldb link.

    00000109
    2.1K followersView on X
CPE platform detail37 entries

37 of 37 entries

PartVendorProductVersionTarget SWTarget HW
OSqnapqts5.2.0.2737--
OSqnapqts5.2.0.2744--
OSqnapqts5.2.0.2782--
OSqnapqts5.2.0.2802--
OSqnapqts5.2.0.2823--
OSqnapqts5.2.0.2851--
OSqnapqts5.2.0.2860--
OSqnapqts5.2.1.2930--
OSqnapqts5.2.2.2950--
OSqnapqts5.2.3.3006--
OSqnapqts5.2.4.3070--
OSqnapqts5.2.4.3079--
OSqnapqts5.2.4.3092--
OSqnapqts5.2.5.3145--
OSqnapqts5.2.6.3195--
OSqnapqts5.2.6.3229--
OSqnapqts5.2.7.3256--
OSqnapqts5.2.7.3297--
OSqnapqts5.2.8.3332--
OSqnapquts_heroh5.2.0.2737--
OSqnapquts_heroh5.2.0.2782--
OSqnapquts_heroh5.2.0.2789--
OSqnapquts_heroh5.2.0.2802--
OSqnapquts_heroh5.2.0.2823--
OSqnapquts_heroh5.2.0.2851--
OSqnapquts_heroh5.2.0.2860--
OSqnapquts_heroh5.2.1.2929--
OSqnapquts_heroh5.2.1.2940--
OSqnapquts_heroh5.2.2.2952--
OSqnapquts_heroh5.2.3.3006--
OSqnapquts_heroh5.2.4.3070--
OSqnapquts_heroh5.2.4.3079--
OSqnapquts_heroh5.2.5.3138--
OSqnapquts_heroh5.2.6.3195--
OSqnapquts_heroh5.2.7.3256--
OSqnapquts_heroh5.2.7.3297--
OSqnapquts_heroh5.2.8.3321--

Explore more