CVE-2025-62847
HIGHDescription
An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later
Is your site exposed to CVE-2025-62847?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | qts |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
| qnap | quts_hero |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-62847? +
How severe is CVE-2025-62847? +
What products are affected by CVE-2025-62847? +
How do I check if I'm vulnerable to CVE-2025-62847? +
Related Vulnerabilities
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the …
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before …
Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of `escapeshellcmd()` in `/components/codegit/traits/execute.php` allows …
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects …
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations …
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior …