Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data

QNAP has addressed multiple security vulnerabilities in its License Center application, potentially preventing unauthorized access to sensitive information and service disruptions on affected NAS devices.

QNAP has addressed multiple security vulnerabilities in its License Center application, potentially preventing unauthorized access to sensitive information and service disruptions on affected NAS devices.

The vulnerabilities, identified as CVE-2025-52871 and CVE-2025-53597, were disclosed on Tue, Jan 3, 2026. Both issues have been classified as moderate severity and have been resolved in the latest software releases. The affected software version is License Center 2.0.x, which is responsible for managing licensing on QNAP systems.

The vulnerabilities require an attacker to have access to a valid account, highlighting the risks associated with credential theft, weak passwords, and exposed administrative portals.

CVE-2025-52871 is an out-of-bounds read vulnerability. If a remote attacker gains access to a user account, they may exploit this flaw to obtain secret data. This type of vulnerability can lead to unintended memory disclosure, potentially exposing tokens, keys, or other sensitive values.

The vulnerabilities, identified as CVE-2025-52871 and CVE-2025-53597, were disclosed on Tue, Jan 3, 2026.
Lucas Gallagher · Thehackingpost

CVE-2025-53597 is a buffer overflow vulnerability. If a remote attacker gains access to an administrator account, they could exploit this vulnerability to modify memory or crash processes, potentially causing system instability or denial-of-service conditions. These vulnerabilities have been fixed in License Center 2.0.36 and later.

Users and organizations using License Center 2.0.x are advised to update immediately, especially if the NAS is accessible from the internet or shared among multiple users.

Advertisement

To update, access the QTS or QuTS hero management interface with administrator privileges, navigate to the App Center from the system menu, search for License Center, select the application, and click Update to complete the process. QNAP acknowledged Coral for reporting these issues.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories