Description


An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.2.6.3195 build 20250715 and later

Related CPE's


o

qnap

quts_hero

18

o

qnap

qts

16

Weaknesses



CWE-770

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-02T15:16:00.017Z

1 week ago

Last modified

2026-01-05T19:47:19.010Z

1 week ago