Format string error in QuTS hero and QNAP QTS - CVE-2025-53591
Published: January 5, 2026
Vulnerability identifier: #VU120944
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-53591
CWE-ID: CWE-134
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to a format string error. A remote administrator can supply a specially crafted input that contains format string specifiers and obtain secret data or modify memory on the target system.
Affected software
QuTS hero
QNAP QTS
QNAP QTS
How to mitigate CVE-2025-53591
Install updates from vendor's website.
QuTS hero - addressed in versions h5.2.7.3256 build 20250913, h5.3.1.3250 build 20250912
QNAP QTS - update to 5.2.7.3256 20250913
QNAP QTS - update to 5.2.7.3256 20250913