QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances)
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 1.2epss 0.4%
from disclosure to weapon25 days
Published on NVDJun 10
1st PoC+25d
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
QTS, QuTS hero, QuTScloud are not affected.
We have already fixed the vulnerability in the following version:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U
public PoCs found — 1
githubgithub.com/Rat5ak/CVE-2025-59382-QNAP-Password-Reset-Account-Takeover★ 1⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.