QNAP has been targeted: security research teams managed to exploit seven critical zero-day vulnerabilities in the company's managed NAS operating systems during the Pwn2Own Ireland 2025 competition . The bugs, identified as CVE-2025-62847, CVE-2025-62848, CVE-2025-62849 (and the corresponding ZDI entries ZDI-CAN-28353, ZDI-CAN-28435, ZDI-CAN-28436), allowed remote code execution (RCE) and privilege escalation in the QTS 5.2.x, QuTS hero h5.2.x and h5.3.x operating systems

The exploits exposed vulnerabilities in both the system core and the web interface, allowing an unauthorized attacker to effectively bypass authentication and gain complete control of the device — compromising both the integrity of the device and the security of stored data.
Exploiting at Pwn2Own: How it happened
At Pwn2Own Ireland 2025, held in Cork from October 20 to 22, teams including Summoning Team, DEVCORE, Team DDOS, and a CyCraftmanaged to combine these zero-day vulnerabilities to achieve authentication bypass and full system takeover on QNAP NAS devices.
See also: Booking.com: New Phishing Attack Targets Travelers Through Compromised Accounts
The main technical issues exploited were improper input validation, buffer overflows, and use-after-free errors in CGI handlers, which allowed the execution of arbitrary commands without user privileges.
For example: researchers exploited stack-based overflows in the quick.cgi component to execute shell commands on uninitialized devices. Then, I moved on to initialized systems via privilege escalation chain attacks.
The choice of NAS devices as targets is not accidental: they are central repositories of information in business and home environments. The use of multiple exploit chains raises the threat to the level of “exploit readiness”.

Troubleshooting and updates from QNAP
QNAP acted promptly: it released firmware updates on October 24, 2025, covering the major operating systems QTS 5.2.x, QuTS hero h5.2.x, and h5.3.x.
In particular:
- QTS 5.2.x users are encouraged to upgrade to version 5.2.7.3297 build 20251024 or later, which incorporates stricter input sanitization and kernel fixes.
- QuTS hero h5.2.x users follow the same version, while h5.3.x requires version 5.3.1.3292 build 20251024 or later.
See also: Landfall spyware targeted Samsung Galaxy phones
Although some CVSS scores have not yet been made public, the zero-day exploit engagement and public demonstration at Pwn2Own rank the vulnerabilities as critical — even with a potential denial of service (DoS) as the first step to a data breach.
Device administrators are advised to use the interface: Control Panel → System → Firmware Update, enabling the “Live Update” option to automatically download and install. For offline environments, manual downloads from the QNAP Download Center support compatibility checking with the product EOL status page.
Additional Security Measures & Corporate Implications
QNAP recommends additional protection measures: immediately changing passwords and separating NAS traffic via VLAN to limit lateral traffic in the event of a successful exploit.
Furthermore, the vulnerabilities do not only concern the main OS but also embedded applications: e.g. the HBS 3 Hybrid Backup Sync (CVE-2025-62840, CVE-2025-62842) allows unauthorized access to backups via path traversal, while Malware Remover (CVE-2025-11837) exhibits a vulnerability in command injection into the scanning engine.
In corporate environments, where NAS devices often act as central repositories for sensitive files, these attack chains are very dangerous.
See also: Amazon WorkSpaces for Linux: Vulnerability allows credential extraction
Security teams should check logs for strange CGI requests, implement intrusion detection systems (IDS), and include the NAS in continuous monitoring as a critical subsystem.

What do we hold in the end?
The chain of seven zero-day vulnerabilities in the QNAP NAS ecosystem also highlights the increasing role of network storage devices as high-risk targets. Timely firmware updates are critical, but not enough: adopting security principles of “minimizing attack surfaces” and enhancing visibility at the network and device levels is now necessary.
Organizations and consumers need to act immediately – not just to “clean” their device of the current problem, but to adopt a security culture where NAS is not considered just “storage,” but a critical part of their security.
