CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-52425

CVSS 9.5v4.0pub. 2025-11-07upd. 2025-11-14

An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QuMagie 2.7.0 and later

🤖 AI Analysis
How it works

An attacker can remotely, without needing to have an account, submit a specially crafted query containing malicious SQL code. The QuMagie application does not properly validate input data, which allows injection and execution of unauthorized commands on the database server side. The attack vector does not require user interaction, however certain special conditions may be required for successful exploitation (AT:P).

Impact

An attacker can execute unauthorized code or commands on the vulnerable system, potentially leading to application takeover, data disclosure or modification, and violation of system integrity and availability as well as related infrastructure.

Mitigation & patch

QuMagie should be updated to version 2.7.0 or newer. Detailed information and patches are available in the official QNAP security bulletin: https://www.qnap.com/en/security-advisory/qsa-25-33

Who is affected

QNAP QuMagie in versions prior to 2.7.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Qnap Qumagie

    APP
    Qnap
    2.6.0 – 2.7.0 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-26237HIGH8.7same product

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then explo...

CVE-2026-44083HIGH8.7same product

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The rem...

CVE-2026-26236HIGH8.7same product

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then explo...

CVE-2025-58464HIGH7.8same product

A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can th...

CVE-2023-47560HIGH7.4same product

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability cou...