CVE-2025-47208 (CNNVD-202601-741)
中文标题:
QNAP Systems QTS和QNAP Systems QuTS hero 安全漏洞
英文标题:
QTS, QuTS hero
漏洞描述
中文描述:
QNAP Systems QTS和QNAP Systems QuTS hero都是中国台湾威联通科技(QNAP Systems)公司的一个具有数据存储与管理功能的软件。 QNAP Systems QTS和QNAP Systems QuTS hero存在安全漏洞,该漏洞源于资源分配无限流或节流,可能导致拒绝服务攻击。
英文描述:
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.2.6.3195 build 20250715 and later
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| QNAP Systems Inc. | QTS | - | < 5.2.6.3195 build 20250715 | - |
cpe:2.3:a:qnap_systems_inc.:qts:*:*:*:*:*:*:*:*
|
| QNAP Systems Inc. | QuTS hero | - | < h5.2.6.3195 build 20250715 | - |
cpe:2.3:a:qnap_systems_inc.:quts_hero:*:*:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.0.2737 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.0.2737:build_20240417:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.0.2782 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.0.2782:build_20240601:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.0.2789 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.0.2789:build_20240607:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.0.2802 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.0.2802:build_20240620:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.0.2823 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.0.2823:build_20240711:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.0.2851 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.0.2851:build_20240808:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.0.2860 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.0.2860:build_20240817:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.1.2929 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.1.2929:build_20241025:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.1.2940 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.1.2940:build_20241105:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.2.2952 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.2.2952:build_20241116:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.3.3006 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.3.3006:build_20250108:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.4.3070 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.4.3070:build_20250312:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.4.3079 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.4.3079:build_20250321:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.5.3138 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.5.3138:build_20250519:*:*:*:*:*:*
|
| qnap | quts_hero | h5.2.6.3195 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.2.6.3195:build_20250715:*:*:*:*:*:*
|
| qnap | quts_hero | h5.3.0.3115 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.3.0.3115:build_20250430:*:*:*:*:*:*
|
| qnap | quts_hero | h5.3.0.3145 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.3.0.3145:build_20250530:*:*:*:*:*:*
|
| qnap | quts_hero | h5.3.0.3192 | - | - |
cpe:2.3:o:qnap:quts_hero:h5.3.0.3192:build_20250716:*:*:*:*:*:*
|
| qnap | qts | 5.2.0.2737 | - | - |
cpe:2.3:o:qnap:qts:5.2.0.2737:build_20240417:*:*:*:*:*:*
|
| qnap | qts | 5.2.0.2744 | - | - |
cpe:2.3:o:qnap:qts:5.2.0.2744:build_20240424:*:*:*:*:*:*
|
| qnap | qts | 5.2.0.2782 | - | - |
cpe:2.3:o:qnap:qts:5.2.0.2782:build_20240601:*:*:*:*:*:*
|
| qnap | qts | 5.2.0.2802 | - | - |
cpe:2.3:o:qnap:qts:5.2.0.2802:build_20240620:*:*:*:*:*:*
|
| qnap | qts | 5.2.0.2823 | - | - |
cpe:2.3:o:qnap:qts:5.2.0.2823:build_20240711:*:*:*:*:*:*
|
| qnap | qts | 5.2.0.2851 | - | - |
cpe:2.3:o:qnap:qts:5.2.0.2851:build_20240808:*:*:*:*:*:*
|
| qnap | qts | 5.2.0.2860 | - | - |
cpe:2.3:o:qnap:qts:5.2.0.2860:build_20240817:*:*:*:*:*:*
|
| qnap | qts | 5.2.1.2930 | - | - |
cpe:2.3:o:qnap:qts:5.2.1.2930:build_20241025:*:*:*:*:*:*
|
| qnap | qts | 5.2.2.2950 | - | - |
cpe:2.3:o:qnap:qts:5.2.2.2950:build_20241114:*:*:*:*:*:*
|
| qnap | qts | 5.2.3.3006 | - | - |
cpe:2.3:o:qnap:qts:5.2.3.3006:build_20250108:*:*:*:*:*:*
|
| qnap | qts | 5.2.4.3070 | - | - |
cpe:2.3:o:qnap:qts:5.2.4.3070:build_20250312:*:*:*:*:*:*
|
| qnap | qts | 5.2.4.3079 | - | - |
cpe:2.3:o:qnap:qts:5.2.4.3079:build_20250321:*:*:*:*:*:*
|
| qnap | qts | 5.2.4.3092 | - | - |
cpe:2.3:o:qnap:qts:5.2.4.3092:build_20250403:*:*:*:*:*:*
|
| qnap | qts | 5.2.5.3145 | - | - |
cpe:2.3:o:qnap:qts:5.2.5.3145:build_20250526:*:*:*:*:*:*
|
| qnap | qts | 5.2.6.3195 | - | - |
cpe:2.3:o:qnap:qts:5.2.6.3195:build_20250715:*:*:*:*:*:*
|
| qnap | qts | 5.2.6.3229 | - | - |
cpe:2.3:o:qnap:qts:5.2.6.3229:build_20250818:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
4.0 (cna)
MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-47208 |
2026-01-04 02:04:15 | 2026-01-12 02:11:51 |
| NVD | nvd_CVE-2025-47208 |
2026-01-06 03:00:03 | 2026-01-12 02:27:49 |
| CNNVD | cnnvd_CNNVD-202601-741 |
2026-01-11 06:15:04 | 2026-01-12 02:38:15 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202601-741
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 2 -> 36
- data_sources: ['cve'] -> ['cve', 'nvd']