Stack-based buffer overflow in QNAP Systems, Inc. products - CVE-2025-68405
Published: June 19, 2026
Vulnerability identifier: #VU134938
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-68405
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error. A remote administrator can trigger stack-based buffer overflow and cause a denial of service condition on the target system.
Affected software
QuTScloud
QuTS hero
QVP (QVR Pro appliances)
QNAP QTS
QuTS hero
QVP (QVR Pro appliances)
QNAP QTS
How to mitigate CVE-2025-68405
Install updates from vendor's website.
QuTScloud - update to
QuTScloud - update to c5.2.9
QuTS hero - update to h5.2.9
QVP (QVR Pro appliances) - update to 2.8.0
QNAP QTS - update to 5.2.10
QuTScloud - update to c5.2.9
QuTS hero - update to h5.2.9
QVP (QVR Pro appliances) - update to 2.8.0
QNAP QTS - update to 5.2.10