Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data

Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data

Posted on January 5, 2026January 5, 2026 By CWS

QNAP has patched a number of safety vulnerabilities in its License Heart utility that would permit attackers to entry delicate data or disrupt providers on affected NAS gadgets.

The problems, tracked as CVE-2025-52871 and CVE-2025-53597, have been disclosed on January 3, 2026.

QNAP rated the issues as Reasonable severity and confirmed that the problems have been resolved within the newest releases. The vulnerabilities have an effect on License Heart 2.0.x, a element used to handle licensing on QNAP programs.

Whereas the bugs aren’t described as unauthenticated distant exploits, QNAP notes that an attacker would first want entry to a legitimate account.

Which makes credential theft, weak passwords, or uncovered admin portals key danger elements.

Overview of the Safety Flaws

CVE-2025-52871 is an out-of-bounds learn vulnerability. In line with QNAP, if a distant attacker beneficial properties entry to a consumer account, they might exploit the flaw to acquire secret information.

CVE IDVulnerability TypeAffected ProductImpactCVE-2025-52871Out-of-bounds ReadLicense Heart 2.0.xA distant attacker with admin account can modify reminiscence or crash processesCVE-2025-53597Buffer OverflowLicense Heart 2.0.xA distant attacker with an admin account can modify reminiscence or crash processes

Out-of-bounds learn points sometimes permit unintended reminiscence disclosure, which might expose tokens, keys, or different delicate values relying on what’s saved in reminiscence throughout execution.

CVE-2025-53597 is a buffer overflow vulnerability. QNAP states that if a distant attacker beneficial properties entry to an administrator account.

They might exploit it to modify reminiscence or crash processes, probably inflicting instability or denial-of-service on affected programs. QNAP has mounted the vulnerabilities in License Heart 2.0.36 and later.

Organizations and residential customers working License Heart 2.0.x ought to replace instantly, particularly if the NAS is reachable from the web or shared throughout many customers.

Entry the QTS or QuTS hero administration interface and authenticate with administrator privileges. Navigate to App Heart from the system menu.

In App Heart, use the search operate to find License Heart. Choose the applying and click on Replace. Affirm the replace when prompted to finish the method. QNAP credited Coral for reporting the problems.

Comply with us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:Attackers, Data, Multiple, Obtain, QNAP, Secret, Tools, Vulnerabilities

Post navigation

Previous Post: Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network
Next Post: AI-based Red Team Toolkit for Penetration Testing With Nmap and Metasploit

Related Posts

Hackers Exploiting Critical Langflow Vulnerability to Deploy Flodrix Botnet and Take System Control Hackers Exploiting Critical Langflow Vulnerability to Deploy Flodrix Botnet and Take System Control Cyber Security News
SharePoint 0-Day RCE Vulnerability Actively Exploited in the Wild to Gain Full Server Access SharePoint 0-Day RCE Vulnerability Actively Exploited in the Wild to Gain Full Server Access Cyber Security News
Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide Cyber Security News
FortiOS and FortiSwitchManager Vulnerability Let Remote Attackers Execute Arbitrary Code FortiOS and FortiSwitchManager Vulnerability Let Remote Attackers Execute Arbitrary Code Cyber Security News
Hacktivist Groups Attacks on Critical ICS Systems to Steal Sensitive Data Hacktivist Groups Attacks on Critical ICS Systems to Steal Sensitive Data Cyber Security News
New Elastic EDR 0-Day Vulnerability Allows Attackers to Bypass Detection, Execute Malware, and Cause BSOD New Elastic EDR 0-Day Vulnerability Allows Attackers to Bypass Detection, Execute Malware, and Cause BSOD Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News