CVE-2025-62849 - QTS, QuTS hero

CVE-2025-62849 - QTS, QuTS hero

CVE ID : CVE-2025-62849 Published : Dec. 16, 2025, 3:15 a.m. | 29 minutes ago Description : An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later Severity: 5.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 16, 2025
Impact: SQL injection

Source: Telegram CVE Monitor