Story perspectives
QNAP Addresses Critical Vulnerabilities, Urges Immediate Updates
11/10/2025
23 5
1 of 1
Story summary
- QNAP addressed seven critical zero-day vulnerabilities in its NAS operating systems disclosed during Pwn2Own Ireland 2025 in Cork (October 20–22, 2025).
- The flaws allow remote code execution and privilege escalation and are CVE-2025-62847, CVE-2025-62848, CVE-2025-62849 due to improper input validation.
- QNAP released firmware updates on October 24, 2025 to mitigate these issues.
- Users should update their systems and apply security measures, including password rotations and traffic segmentation, to reduce risk.
