Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data
QNAP has addressed multiple security vulnerabilities in its License Center application, potentially preventing unauthorized access to sensitive information and service disruptions on affected NAS devices.
QNAP has addressed multiple security vulnerabilities in its License Center application, potentially preventing unauthorized access to sensitive information and service disruptions on affected NAS devices.
The vulnerabilities, identified as CVE-2025-52871 and CVE-2025-53597, were disclosed on Tue, Jan 3, 2026. Both issues have been classified as moderate severity and have been resolved in the latest software releases. The affected software version is License Center 2.0.x, which is responsible for managing licensing on QNAP systems.
The vulnerabilities require an attacker to have access to a valid account, highlighting the risks associated with credential theft, weak passwords, and exposed administrative portals.
CVE-2025-52871 is an out-of-bounds read vulnerability. If a remote attacker gains access to a user account, they may exploit this flaw to obtain secret data. This type of vulnerability can lead to unintended memory disclosure, potentially exposing tokens, keys, or other sensitive values.
The vulnerabilities, identified as CVE-2025-52871 and CVE-2025-53597, were disclosed on Tue, Jan 3, 2026.
CVE-2025-53597 is a buffer overflow vulnerability. If a remote attacker gains access to an administrator account, they could exploit this vulnerability to modify memory or crash processes, potentially causing system instability or denial-of-service conditions. These vulnerabilities have been fixed in License Center 2.0.36 and later.
Users and organizations using License Center 2.0.x are advised to update immediately, especially if the NAS is accessible from the internet or shared among multiple users.
To update, access the QTS or QuTS hero management interface with administrator privileges, navigate to the App Center from the system menu, search for License Center, select the application, and click Update to complete the process. QNAP acknowledged Coral for reporting these issues.
Based on reporting by Cyber Security News.
