A path traversal vulnerability has been reported to affect several QNAP operating system versions. (CVE-2025-30271)
A path traversal vulnerability (CVE-2025-30271) affects multiple versions of QNAP operating systems. This vulnerability allows a remote attacker with a user account to read unauthorized files or system data. The issue has been addressed and fixed in QTS version 5.2.5.3145 build 20250526 and later, as well as QuTS hero version h5.2.5.3138 build 20250519 and later. The vulnerability has a medium severity rating with a CVSS score of 6.5.
AI Analysis
Technical Summary
CVE-2025-30271 is a path traversal vulnerability in several QNAP operating system versions. An attacker who has obtained a user account can exploit this flaw to access files outside the intended directory scope, potentially exposing sensitive system data. The vulnerability is classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). Official fixes have been released in QTS 5.2.5.3145 build 20250526 and QuTS hero h5.2.5.3138 build 20250519.
Potential Impact
An attacker with a valid user account can exploit this vulnerability to read files that should be inaccessible, potentially leading to unauthorized disclosure of sensitive information. The vulnerability does not impact integrity or availability, only confidentiality.
Mitigation Recommendations
Upgrade affected QNAP operating systems to QTS 5.2.5.3145 build 20250526 or later, or QuTS hero h5.2.5.3138 build 20250519 or later. Applying these official fixes fully mitigates the vulnerability.
A path traversal vulnerability has been reported to affect several QNAP operating system versions. (CVE-2025-30271)
Description
A path traversal vulnerability (CVE-2025-30271) affects multiple versions of QNAP operating systems. This vulnerability allows a remote attacker with a user account to read unauthorized files or system data. The issue has been addressed and fixed in QTS version 5.2.5.3145 build 20250526 and later, as well as QuTS hero version h5.2.5.3138 build 20250519 and later. The vulnerability has a medium severity rating with a CVSS score of 6.5.
CVSS v3.1
Score 6.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-30271 is a path traversal vulnerability in several QNAP operating system versions. An attacker who has obtained a user account can exploit this flaw to access files outside the intended directory scope, potentially exposing sensitive system data. The vulnerability is classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). Official fixes have been released in QTS 5.2.5.3145 build 20250526 and QuTS hero h5.2.5.3138 build 20250519.
Potential Impact
An attacker with a valid user account can exploit this vulnerability to read files that should be inaccessible, potentially leading to unauthorized disclosure of sensitive information. The vulnerability does not impact integrity or availability, only confidentiality.
Mitigation Recommendations
Upgrade affected QNAP operating systems to QTS 5.2.5.3145 build 20250526 or later, or QuTS hero h5.2.5.3138 build 20250519 or later. Applying these official fixes fully mitigates the vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-39x8-8q4p-7578
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-30271"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab74f38f7a7c54106e138e6
Added to database: 09/26/2026, 04:51:04 UTC
Last enriched: 09/26/2026, 04:59:57 UTC
Last updated: 09/27/2026, 02:40:07 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.