PatchSiren cyber security CVE debrief
CVE-2025-66273 QNAP Systems Inc. CVE debrief
CVE-2025-66273 is a high-severity command injection vulnerability affecting several QNAP operating system versions. An attacker with administrator privileges, after gaining access, can exploit this vulnerability to execute arbitrary commands. The vulnerability has been addressed in the following versions: QTS 5.2.9.3410 build 20260214 and later, QuTS hero h5.2.9.3410 build 20260214 and later, QuTS hero h5.3.4.3500 build 20260520 and later, and QuTS hero h6.0.0.3397 build 20260206 and later.
- Vendor
- QNAP Systems Inc.
- Product
- QTS
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-10
- Original CVE updated
- 2026-06-15
- Advisory published
- 2026-06-10
- Advisory updated
- 2026-06-15
Who should care
Administrators and users of QNAP operating systems, particularly those using versions prior to QTS 5.2.9.3410 build 20260214, QuTS hero h5.2.9.3410 build 20260214, QuTS hero h5.3.4.3500 build 20260520, and QuTS hero h6.0.0.3397 build 20260206.
Technical summary
The vulnerability, tracked as CVE-2025-66273, allows an attacker with administrator privileges to execute arbitrary commands after gaining access. It is categorized under CWE-78 and has a CVSS score of 8.6, indicating high severity.
Defensive priority
High
Recommended defensive actions
- Upgrade to the fixed versions: QTS 5.2.9.3410 build 20260214 or later, QuTS hero h5.2.9.3410 build 20260214 or later, QuTS hero h5.3.4.3500 build 20260520 or later, and QuTS hero h6.0.0.3397 build 20260206 or later.
- Restrict access to administrator accounts to minimize the risk of exploitation.
- Monitor QNAP security advisories for further updates and patches.
Evidence notes
The CVE-2025-66273 vulnerability was reported to affect several QNAP operating system versions. The vendor, QNAP, has provided fixes for this issue in the specified versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-66273 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-66273
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-66273 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66273
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.qnap.com/en/security-advisory/qsa-26-10
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.