CVE-2025-59386 Details
Description
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build 20251225 and later
A NULL pointer dereference vulnerability has been identified in QNAP QuTS hero operating system versions 5.3.x. This vulnerability allows remote attackers with administrator access to exploit the issue, resulting in a denial-of-service (DoS) condition.
Users can update to QuTS hero version 5.3.2.3354 build 20251225 or later to address this vulnerability. Instructions for updating QuTS hero are available on the QNAP website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.qnap.com/en/security-advisory/qsa-26-08 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qnap quts hero | h5.3.0.3115 build_20250430 h5.3.0.3145 build_20250530 h5.3.0.3192 build_20250716 h5.3.1.3250 build_20250912 h5.3.1.3292 build_20251024 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 12, 2026 | Initial Analysis | [email protected] |
| Feb 11, 2026 | New CVE Received | [email protected] |