QNAP QuTS Hero NULL Pointer Dereference Vulnerability Leading to Denial-of-Service

Vulnerability

A NULL pointer dereference vulnerability has been identified in QNAP QuTS hero operating system versions 5.3.x. This vulnerability allows remote attackers with administrator access to exploit the issue, resulting in a denial-of-service (DoS) condition.

Impact

Exploitation of this vulnerability causes a denial-of-service condition, leading to a crash or unresponsiveness of the affected system.

Remediation

Users can update to QuTS hero version 5.3.2.3354 build 20251225 or later to address this vulnerability. Instructions for updating QuTS hero are available on the QNAP website.

Added: Feb 11, 2026, 1:21 PM
Updated: Feb 11, 2026, 4:06 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
2.5
exploitability
4.8
remediation
7.7
relevance
3.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.