n improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later
| Link | Resource |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-45 | Vendor Advisory |
Configuration 1 (hide)
|
Configuration 2 (hide)
|
17 Dec 2025, 13:56
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-12-16 03:15
Updated : 2025-12-17 13:56
NVD link : CVE-2025-62847
Mitre link : CVE-2025-62847
CVE.ORG link : CVE-2025-62847
JSON object : View
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')