An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic.
We have already fixed the vulnerability in the following versions:
QTS 5.2.7.3297 build 20251024 and later
QuTS hero h5.2.7.3297 build 20251024 and later
QuTS hero h5.3.1.3292 build 20251024 and later
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-45 |
|
History
Tue, 16 Dec 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later | |
| Title | QTS, QuTS hero | |
| First Time appeared |
Qnap Systems Inc.
Qnap Systems Inc. qts Qnap Systems Inc. quts Hero |
|
| Weaknesses | CWE-88 | |
| CPEs | cpe:2.3:a:qnap_systems_inc.:qts:*:*:*:*:*:*:*:* cpe:2.3:a:qnap_systems_inc.:quts_hero:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Qnap Systems Inc.
Qnap Systems Inc. qts Qnap Systems Inc. quts Hero |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published: 2025-12-16T02:25:11.210Z
Updated: 2025-12-16T21:25:23.090Z
Reserved: 2025-10-24T02:43:45.373Z
Link: CVE-2025-62847
No data.
Status : Awaiting Analysis
Published: 2025-12-16T03:15:58.200
Modified: 2025-12-16T14:10:11.300
Link: CVE-2025-62847
No data.