{"id":9650,"date":"2026-01-05T10:03:57","date_gmt":"2026-01-05T10:03:57","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/05\/multiple-vulnerabilities-in-qnap-tools-let-attackers-obtain-secret-data\/"},"modified":"2026-01-05T10:03:57","modified_gmt":"2026-01-05T10:03:57","slug":"multiple-vulnerabilities-in-qnap-tools-let-attackers-obtain-secret-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/05\/multiple-vulnerabilities-in-qnap-tools-let-attackers-obtain-secret-data\/","title":{"rendered":"Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data"},"content":{"rendered":"<p>    Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>QNAP has patched multiple security vulnerabilities in its\u00a0License Center\u00a0application that could allow attackers to\u00a0access sensitive information\u00a0or\u00a0disrupt services\u00a0on affected NAS devices.<\/p>\n<p>The issues, tracked as\u00a0CVE-2025-52871\u00a0and\u00a0CVE-2025-53597, were disclosed on\u00a0January 3, 2026.<\/p>\n<p>QNAP rated the flaws as\u00a0Moderate\u00a0severity and confirmed that the issues have been resolved in the latest releases. The vulnerabilities affect\u00a0License Center 2.0.x, a component used to manage licensing on <a href=\"https:\/\/cybersecuritynews.com\/qnap-backup-software-net-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">QNAP systems<\/a>.<\/p>\n<p>While the bugs are not described as unauthenticated remote exploits, QNAP notes that an attacker would first need access to a valid account.<\/p>\n<p>Which makes\u00a0<a href=\"https:\/\/cybersecuritynews.com\/how-businesses-prevent-credential-theft-with-early-phishing-detection\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential theft<\/a>,\u00a0weak passwords, or\u00a0exposed admin portals\u00a0key risk factors.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-overview-of-the-security-flaws\"><strong>Overview of the Security Flaws<\/strong><\/h2>\n<p>CVE-2025-52871\u00a0is an\u00a0<a href=\"https:\/\/cybersecuritynews.com\/out-of-bounds-read-and-write\/\" target=\"_blank\" rel=\"noreferrer noopener\">out-of-bounds<\/a> read\u00a0vulnerability. According to QNAP, if a remote attacker gains access to a\u00a0user account, they may exploit the flaw to\u00a0obtain secret data.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">CVE ID<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Vulnerability Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Affected Product<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Impact<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2025-52871<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Out-of-bounds Read<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">License Center 2.0.x<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">A remote attacker with admin account can modify memory or crash processes<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2025-53597<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Buffer Overflow<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">License Center 2.0.x<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">A remote attacker with an admin account can modify memory or crash processes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Out-of-bounds read issues typically allow unintended memory disclosure, which can expose <a href=\"https:\/\/cybersecuritynews.com\/shai-hulud-2-0-malware-attack-compromised-30000-repositories\/\" target=\"_blank\" rel=\"noreferrer noopener\">tokens<\/a>, keys, or other sensitive values depending on what is stored in memory during execution.<\/p>\n<p>CVE-2025-53597\u00a0is a\u00a0<a href=\"https:\/\/cybersecuritynews.com\/cisa-d-link-routers-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">buffer overflow<\/a>\u00a0vulnerability. QNAP states that if a remote attacker gains access to an\u00a0administrator account.<\/p>\n<p>They could exploit it to\u00a0modify memory or crash processes, potentially <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">causing instability or\u00a0<a href=\"https:\/\/cybersecuritynews.com\/multiple-django-vulnerabilities\/\" target=\"_blank\" rel=\"noopener\">denial-of-service<\/a>\u00a0<\/span>on affected systems. QNAP has fixed the vulnerabilities in\u00a0License Center 2.0.36 and later.<\/p>\n<p>Organizations and home users running\u00a0License Center 2.0.x\u00a0should update immediately, especially if the NAS is reachable from the internet or shared across many users.<\/p>\n<p>Access the QTS or QuTS hero management interface and authenticate with administrator <a href=\"https:\/\/cybersecuritynews.com\/k7-antivirus-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">privileges<\/a>. Navigate to App Center from the system menu.<\/p>\n<p>In App Center, use the search function to locate License Center. Select the application and click Update. Confirm the update when prompted to complete the process. QNAP credited\u00a0Coral\u00a0for <a href=\"https:\/\/www.qnap.com\/en\/security-advisory\/qsa-25-52\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reporting<\/a> the issues.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/qnap-tools-vulnerabilities\/\">Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/qnap-tools-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data QNAP has patched multiple security vulnerabilities in its\u00a0License Center\u00a0application that could allow attackers to\u00a0access sensitive information\u00a0or\u00a0disrupt services\u00a0on affected NAS devices. The issues, tracked as\u00a0CVE-2025-52871\u00a0and\u00a0CVE-2025-53597, were disclosed on\u00a0January 3, 2026. QNAP rated the flaws as\u00a0Moderate\u00a0severity and confirmed that the issues have been resolved in the latest [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-9650","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9650"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9650"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9650\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9650"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9650"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}