An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and later
QuTS hero h5.2.9.3410 build 20260214 and later
QuTS hero h5.3.4.3500 build 20260520 and later
QuTS hero h6.0.0.3397 build 20260206 and later
Security readout for executives and security teams
Plain-English summary
This is a QNAP NAS operating-system flaw that matters most after an attacker already has administrator access. With that access, the attacker could use an integer handling bug to weaken or compromise system security. The vendor has released fixed QTS and QuTS hero builds.
Executive priority
Treat this as a scheduled but important NAS maintenance item. It is not presented as actively exploited, but QNAP NAS devices often hold business-critical data, and administrator-account compromise would make this vulnerability more dangerous.
Technical view
CVE-2025-66280 is reported as an integer overflow or wraparound issue, with CWE-190 and CWE-121 classifications. CVSS 4.0 is 5.1: network reachable, low complexity, no user interaction, but high privileges required. Reported impact is low integrity and availability impact, with no confidentiality impact in the CVSS vector.
Likely exposure
Exposure is most likely on QNAP NAS devices running QTS or QuTS hero below the vendor-listed fixed builds. The public data gives limited affected-version detail, so teams should verify exact installed OS versions against QNAP advisory QSA-26-10.
Exploitation context
The provided sources do not show active exploitation, and the CVE is not listed as KEV in the bundle. Exploitation requires a remote attacker to have an administrator account first, which reduces broad internet-scale risk but raises urgency where admin credentials may be exposed or reused.
Researcher notes
The strongest source is QNAP’s advisory. Public details do not describe exploit mechanics, affected components, or operational indicators. Version mapping is incomplete in the CVE bundle, so validation should rely on exact firmware/build comparison rather than CPE matching.
Mitigation direction
Upgrade QTS to 5.2.9.3410 build 20260214 or later.
Upgrade QuTS hero h5.2 to h5.2.9.3410 build 20260214 or later.
Upgrade QuTS hero h5.3 to h5.3.4.3500 build 20260520 or later.
Upgrade QuTS hero h6.0 to h6.0.0.3397 build 20260206 or later.
Review QNAP advisory QSA-26-10 for product-specific guidance.
Validation and detection
Inventory QNAP NAS devices and record QTS or QuTS hero versions.
Compare installed builds with the fixed versions in QSA-26-10.
Review administrator accounts for unexpected, stale, or shared access.
Check logs for suspicious administrator activity before and after patching.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-121: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.