PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-66273 QNAP Systems Inc. CVE debrief

CVE-2025-66273 is a high-severity command injection vulnerability affecting several QNAP operating system versions. An attacker with administrator privileges, after gaining access, can exploit this vulnerability to execute arbitrary commands. The vulnerability has been addressed in the following versions: QTS 5.2.9.3410 build 20260214 and later, QuTS hero h5.2.9.3410 build 20260214 and later, QuTS hero h5.3.4.3500 build 20260520 and later, and QuTS hero h6.0.0.3397 build 20260206 and later.

Vendor
QNAP Systems Inc.
Product
QTS
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-10
Original CVE updated
2026-06-15
Advisory published
2026-06-10
Advisory updated
2026-06-15

Who should care

Administrators and users of QNAP operating systems, particularly those using versions prior to QTS 5.2.9.3410 build 20260214, QuTS hero h5.2.9.3410 build 20260214, QuTS hero h5.3.4.3500 build 20260520, and QuTS hero h6.0.0.3397 build 20260206.

Technical summary

The vulnerability, tracked as CVE-2025-66273, allows an attacker with administrator privileges to execute arbitrary commands after gaining access. It is categorized under CWE-78 and has a CVSS score of 8.6, indicating high severity.

Defensive priority

High

Recommended defensive actions

  • Upgrade to the fixed versions: QTS 5.2.9.3410 build 20260214 or later, QuTS hero h5.2.9.3410 build 20260214 or later, QuTS hero h5.3.4.3500 build 20260520 or later, and QuTS hero h6.0.0.3397 build 20260206 or later.
  • Restrict access to administrator accounts to minimize the risk of exploitation.
  • Monitor QNAP security advisories for further updates and patches.

Evidence notes

The CVE-2025-66273 vulnerability was reported to affect several QNAP operating system versions. The vendor, QNAP, has provided fixes for this issue in the specified versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-66273 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-66273

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-66273 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66273

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.