A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and later
QuTS hero h5.2.9.3410 build 20260214 and later
QuTS hero h5.3.2.3354 build 20251225 and later
QuTS hero h6.0.0.3397 build 20260206 and later
Security readout for executives and security teams
Plain-English summary
CVE-2025-66274 is a QNAP QTS and QuTS hero denial-of-service issue. A remote attacker must first have an administrator account, so the main business risk is outage from a compromised or misused admin account rather than unauthenticated takeover.
Executive priority
Treat this as a routine but time-bound availability fix for QNAP NAS environments. Prioritize systems with sensitive operations, internet-reachable administration, or weak administrator account control.
Technical view
The issue is a CWE-476 NULL pointer dereference affecting several QNAP operating system versions. The CVSS 4.0 score is 5.1 with network attack vector, low complexity, high privileges required, no user interaction, limited integrity and availability impact, and no confidentiality impact reported.
Likely exposure
Exposure is most relevant for QNAP NAS systems running affected QTS or QuTS hero versions below the fixed builds listed by QNAP, especially where administrator accounts are exposed to compromise or shared operationally.
Exploitation context
The provided sources do not report active exploitation, and the CVE is not marked as KEV. Exploitation requires a remote attacker to already have administrator privileges, limiting opportunistic risk but leaving insider or credential-compromise scenarios important.
Researcher notes
Evidence supports a NULL pointer dereference leading to DoS after administrator authentication. The source bundle does not provide crash details, affected code paths, proof-of-concept status, or exploit telemetry, so validation should remain version and access-control based.
Mitigation direction
Upgrade QTS to 5.2.9.3410 build 20260214 or later.
Upgrade QuTS hero to the applicable fixed build listed by QNAP.
Review QNAP administrator accounts for unnecessary or shared access.
Restrict administrative access to trusted management paths where possible.
Check QNAP advisory QSA-26-08 for any newer vendor guidance.
Validation and detection
Inventory QNAP devices running QTS or QuTS hero.
Compare installed versions and builds against QNAP's fixed-version list.
Confirm whether any affected systems are reachable for remote administration.
Review administrator account ownership and recent privileged access.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-476: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-476 · source CWE mapping
NULL Pointer Dereference
NULL Pointer Dereference represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.