
QNAP fixes 7 critical NAS bugs discovered at Pwn2Own Ireland 2025
QNAP has fixed seven critical zero-day vulnerabilities in its Network Attached Storage (NAS) operating systems after a group of researchers successfully exploited them at Pwn2Own Ireland 2025 , held in Cork from October 20 to 22. In a controlled environment, the demonstrated exploits expose kernel-level vulnerabilities and web interface flaws that could allow unauthenticated attackers to compromise the device and exfiltrate data stored there. To find the flaws, Summoning Team, DEVCORE, Team DDOS, and a CyCraft intern chained these zero-days together to bypass authentication and gain complete system control over QNAP NAS devices. These flaws, identified as CVE-2025-62847, CVE-2025-62848, CVE-2025-62849, allow remote










