QNAP QSA-26-10: Multiple Injection and Memory-Safety Vulnerabilities in QTS, QuTS hero, QuTS cloud, QVP, and File Station (CVE-2025-66273, CVE-2026-26240, and 12 others) — Threadlinqs Intelligence
As of 2026-06-22, QNAP QSA-26-10: Multiple Injection and Memory-Safety Vulnerabilities in QTS, QuTS hero, QuTS cloud, QVP, and File Station (CVE-2025-66273, CVE-2026-26240, and 12 others) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-0901 · Severity: HIGH · CVSS: 9.1 · Status: PATCHED · Category: VULNERABILITY
QNAP advisory QSA-26-10 (April 6, 2026) patches 14 vulnerabilities across the QTS, QuTS hero, QuTS cloud, and QVP NAS operating systems and the File Station 5/6 applications, spanning OS command
On April 6, 2026 QNAP published security advisory QSA-26-10 ('Vulnerabilities in QTS, QuTS hero, QuTS cloud, and QVP'), disclosing 14 CVEs that it had already remediated. The bundle affects the core NAS operating systems — QTS 5.2.7, QuTS hero h5.2.8, QuTS cloud c5.2.8, and the QVP (QVR Pro appliance) line 2.7.1 — as well as the File Station 5 and File Station 6 web file-management applications. QNAP assigned an overall 'Important' severity. When NVD published the records on June 9-10, 2026 and assigned metrics on June 17, 2026, individual scores ranged from LOW to CRITICAL, with the two File Station 5 chunked-upload buffer overflows reaching CVSS v3.1 9.1 (CRITICAL).
The most impactful classes are command injection and memory corruption. Three OS command-injection flaws (CVE-2025-66273, CVE-2025-66279, CVE-2026-22893; all CWE-78, CVSS v4.0 8.6 / v3.1 7.2 HIGH) allow a remote attacker who has obtained an administrator account to execute arbitrary OS commands: CVE-2025-66273 injects through the username parameter, CVE-2025-66279 is reachable through user-deletion APIs, and CVE-2026-22893 enables execution with elevated privileges. Because QNAP NAS appliances are frequently exposed to the internet and run privileged daemons, command injection from an admin context is effectively full device takeover.
The memory-safety set centers on the utilRequest.cgi CGI handler and File Station upload paths. CVE-2025-62858 is a stack overflow (CWE-121, v3.1 6.5) reachable by a remote admin to corrupt memory or crash processes. CVE-2025-66280 is an integer overflow/wraparound (CWE-190/CWE-121, v3.1 7.2 HIGH) that an admin can use to compromise system security. CVE-2025-68405 (not yet in NVD; per the advisory) is a stack overflow exploitable by an authenticated admin to cause a DoS. CVE-2026-26239 is a File Station 5 stack-based buffer overflow (CWE-121, v3.1 8.1 HIGH) usable by an authenticated user. CVE-2026-26240 and CVE-2026-26241 are File Station 5 stack-based buffer overflows (CWE-121, v3.1 9.1 CRITICAL) triggered by overly long upload filenames — including during chunked uploads — that overflow buffers in / crash utilRequest.cgi.
The availability and access-control set includes CVE-2025-66281 (NULL pointer dereference, CWE-476, v3.1 7.2) where malformed HTTP requests missing a Content-Length header crash the service; CVE-2026-22899 (NULL pointer dereference in File Station 6, CWE-476, v3.1 6.5) where a low-privileged user triggers a segmentation fault in utilRequest.cgi for DoS; CVE-2026-24724 (incorrect authorization / broken access control in File Station 6, CWE-863, v3.1 8.1 HIGH) letting an authenticated user bypass intended restrictions and reach sensitive files; and CVE-2026-24720 (uncontrolled resource consumption in File Station 6, CWE-770, v3.1 6.5) where an authenticated user exhausts CPU/memory to deny service. CVE-2025-59382 is a URL-injection flaw (CWE-472, external control of an assumed-immutable web parameter, v4.0 1.2 LOW) in a password-reset flow: a remote attacker can modify the password-reset URL to direct a victim to an attacker-controlled reset page, enabling credential theft via social engineering; NVD notes QTS/QuTS hero/QuTScloud themselves are not affected for this specific item, indicating it applies to an associated component bundled into the advisory.
No threat actor, in-the-wild exploitation, or public proof-of-concept code was reported in either the QNAP advisory or the NVD records; most flaws require a valid (often administrator) account, which constrains pre-authentication risk except for the resource-exhaustion and NULL-dereference DoS items. The pragmatic exposure is that QNAP devices are a recurring ransomware target (DeadBolt, Qlocker, eCh0raix historically), so chained credential compromise plus these command-injection and access-control bugs materially raises takeover risk. Defenders should apply the fixed builds immediately (QTS 5.2.9.3410 build 20260214 / branch 5.2.10, QuTS hero h5.2.9, QuTS c
Weaknesses (CWE)
CWE-78, CWE-121, CWE-190, CWE-476, CWE-863, CWE-770, CWE-472
Target sectors: technology, small-medium-business, managed-service-providers, media-and-entertainment, healthcare, education
Target regions: Global
References
- QNAP Security Advisory QSA-26-10: Vulnerabilities in QTS, QuTS hero, QuTS cloud, and QVP
- QNAP Patches Multiple Injection Vulnerabilities
- NVD - CVE-2025-66273 (OS Command Injection, CWE-78)
- NVD - CVE-2025-66279 (OS Command Injection, CWE-78)
- NVD - CVE-2026-22893 (OS Command Injection, CWE-78)
- NVD - CVE-2026-26240 (Stack-based Buffer Overflow, CWE-121, CRITICAL 9.1)
- NVD - CVE-2026-26241 (Stack-based Buffer Overflow, CWE-121, CRITICAL 9.1)
- NVD - CVE-2026-26239 (File Station 5 Buffer Overflow, CWE-121)
- NVD - CVE-2025-62858 (Buffer/Stack Overflow, CWE-121)
- NVD - CVE-2025-66280 (Integer Overflow, CWE-190/CWE-121)
- NVD - CVE-2025-66281 (NULL Pointer Dereference, CWE-476)
- NVD - CVE-2026-24724 (Incorrect Authorization, CWE-863)
- NVD - CVE-2026-24720 (Uncontrolled Resource Consumption, CWE-770)
- NVD - CVE-2026-22899 (NULL Pointer Dereference, CWE-476)
- NVD - CVE-2025-59382 (URL Injection / External Control of Web Parameter, CWE-472)
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2025-66273, CVE-2025-66279, CVE-2026-22893, CVE-2025-59382, CVE-2025-62858, CVE-2025-68405, CVE-2026-26239, CVE-2026-26240, CVE-2026-26241, CVE-2025-66280, T1598, T1190, T1078, T1566, T1059, T1068, T1211, T1212, T1083, T1082