A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. (CVE-2025-30272)
A NULL pointer dereference vulnerability (CVE-2025-30272) affects several versions of QNAP operating systems. This flaw allows a remote attacker with a user account to cause a denial-of-service (DoS) condition. The vulnerability has been fixed in QTS version 5.2.5.3145 build 20250526 and later, and QuTS hero version h5.2.5.3138 build 20250519 and later.
AI Analysis
Technical Summary
CVE-2025-30272 is a NULL pointer dereference vulnerability in multiple QNAP operating system versions. Exploitation requires the attacker to have a user account, after which they can trigger a denial-of-service attack by causing the system to dereference a NULL pointer. The vulnerability has been addressed by QNAP in specific builds of QTS and QuTS hero operating systems released in May 2025.
Potential Impact
Successful exploitation results in denial-of-service (DoS) with no impact on confidentiality or integrity. The attacker must have user-level privileges to exploit this vulnerability remotely.
Mitigation Recommendations
The vulnerability is fixed in QTS 5.2.5.3145 build 20250526 and later, and QuTS hero h5.2.5.3138 build 20250519 and later. Users should upgrade to these versions or later to remediate the issue.
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. (CVE-2025-30272)
Description
A NULL pointer dereference vulnerability (CVE-2025-30272) affects several versions of QNAP operating systems. This flaw allows a remote attacker with a user account to cause a denial-of-service (DoS) condition. The vulnerability has been fixed in QTS version 5.2.5.3145 build 20250526 and later, and QuTS hero version h5.2.5.3138 build 20250519 and later.
CVSS v3.1
Score 6.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-30272 is a NULL pointer dereference vulnerability in multiple QNAP operating system versions. Exploitation requires the attacker to have a user account, after which they can trigger a denial-of-service attack by causing the system to dereference a NULL pointer. The vulnerability has been addressed by QNAP in specific builds of QTS and QuTS hero operating systems released in May 2025.
Potential Impact
Successful exploitation results in denial-of-service (DoS) with no impact on confidentiality or integrity. The attacker must have user-level privileges to exploit this vulnerability remotely.
Mitigation Recommendations
The vulnerability is fixed in QTS 5.2.5.3145 build 20250526 and later, and QuTS hero h5.2.5.3138 build 20250519 and later. Users should upgrade to these versions or later to remediate the issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3gcv-ff7j-4x62
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-30272"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab74f37f7a7c54106e138e0
Added to database: 09/26/2026, 04:51:03 UTC
Last enriched: 09/26/2026, 04:59:35 UTC
Last updated: 09/27/2026, 02:40:03 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.